Four signals turn repeated playtest reports into issue clusters
Repro scores an incoming report with four inputs: text similarity, nearby game state, normalized log signatures, and environment overlap. A scene mismatch blocks a merge, while three score bands decide whether the report joins an issue, waits for studio confirmation, or becomes a new cluster. The method is deterministic and runs offline, so teams can inspect why two reports were grouped instead of trusting a remote model.
The rest of the product follows that decision. A tester opens an F1 report overlay, the server authenticates the grant, and the studio board receives updates over server-sent events. Staff can confirm a possible duplicate, split it, or verify the issue. Verification feeds a virtual-coin ledger. An optional Anthropic key only enriches titles, leaving the central ingest path usable without a hosted model credential.
The 392 passing tests are stronger than the failed build
Our run installed 442 pnpm packages in 29 seconds and used 739 MB on disk. The repository contained 229 files, roughly 28,998 source lines, one CI workflow, a tests directory, and workspace configuration. A Compose file starts PostgreSQL, but there is no Dockerfile for the application. This is a compact Next.js codebase by platform standards, with a manageable contributor install.
The build script runs Prisma client generation, database migrations, and the Next.js build in one command. Prisma validated the schema first and returned P1012 because DATABASE_URL was missing. The command exited after 11 seconds. The log proves a required environment variable was absent; it does not prove the Next.js application cannot compile once a database URL is supplied.
What happened when we ran it
Our unprivileged Node 22 sandbox gave commit 4e18adc 3 CPUs, 8 GB of RAM, and no secrets. Pnpm completed installation in 29 seconds. The 739 MB result covers installed packages, not a running Postgres volume or uploaded playtest assets. Repro asks for Node 20, so a serious evaluation should use that documented runtime even though installation and tests completed in our Node 22 image.
The build failed in 11 seconds with Prisma error P1012: Environment variable not found: DATABASE_URL. Its schema reads that value for PostgreSQL. Calling this a compiler defect would overreach, while calling the build successful would be false. The practical finding is that pnpm build couples compilation to database configuration and migrations.
Vitest completed in 21 seconds with 392 passed and 0 failed. The README separates domain and UI tests from database integration tests, while our measurement reports the executed Vitest total without claiming every production path was exercised. The passing suite supports the deterministic logic, but it does not cancel the missing build configuration or license.
A 65,535-grant watermark still cannot stop forwarding
Hosted web frames can embed a 16-bit tester identity, setting a stated ceiling of 65,535 distinct grants. The README draws a useful limit: compressed report JPEGs contain no watermark, lossless exported PNG frames can carry one, and hosted downloads do not watermark every rendered frame. A tester with memory inspection or hardware capture can bypass client-side controls. Repro calls the result accountability rather than perfect DRM.
Link-only, hosted web, and hosted download modes all say they cannot stop a tester passing the build onward. Browser-bound grants, 15-minute tokens, append-only access events, and user-agent matching can record or reject some access, but possession eventually moves outside the server's control. Evaluate Repro as evidence and friction around leaks, never as proof that an unreleased binary cannot escape.
Three secrets and Postgres are the local operating minimum
The documented local path uses Node 20 and PostgreSQL 16 on host port 5434. DATABASE_URL points Prisma at that database. SESSION_SECRET, ACCESS_SECRET, and APP_SALT must each reach 32 characters outside development and test, while an Anthropic key is optional. The access key can mint grants, and the salt protects stored IP hashes, so these values need normal secret controls.
Repro stores campaigns, reports, grants, NDA signatures, identity photos, rewards, and access events. Raw IP addresses are hashed, but the remaining records are still sensitive. The small 1.3 MB checkout says nothing about that operating burden. A studio needs retention, deletion, backup, and restore rules before real testers upload identity material or accept legal text.
No license and no built self-hosted mode limit adoption
GitHub reported no detected license, and the 229-file tree contained no LICENSE or COPYING file. Source visibility alone does not provide the permissions companies expect from open-source software. The README also describes self-hosting as a roadmap line and an annual license. A buyer needs written terms from the owners before treating this code as reusable infrastructure.
Commercial plumbing is incomplete too. Repro can store a selected plan and append plan changes, but the README says it takes no payment in-app and invoices separately. Reward fulfilment is manual. Those choices are reasonable for a hackathon entry, yet they make the pricing page a proposal rather than a finished billing system.
A September 13 push and zero releases mark a young snapshot
The repository was created on September 10, 2026 and last pushed on September 13. GitHub showed 212 stars, zero open issues and pull requests, and no published release on October 2. Those facts describe a short hackathon burst, not abandonment. They also provide no evidence of tagged upgrades or outside issue handling yet.
Repro's best idea is narrow: deterministic clustering can make a noisy playtest board usable without sending reports to an AI service. The 392 passing tests support that core. Licensing, self-hosted delivery, payments, and database-coupled builds keep it in evaluation territory. Pilot the report-to-cluster loop with disposable data, then wait for explicit reuse terms before putting it into a release process.

