An AI-powered code review agent that analyzes pull requests for bugs, security vulnerabilities, performance issues, and style consistency.
Sample DocumentThe Code Review Agent integrates into your GitHub/GitLab CI pipeline to automatically review every pull request. It identifies bugs, security vulnerabilities, performance issues, and deviations from your team's coding standards.
| Metric | Value |
|---|---|
| Languages Supported | Python, JavaScript/TypeScript, Go, Java, Rust, C++ |
| Avg. Review Time | 45 seconds per PR |
| Bug Detection Rate | 82% of critical bugs caught |
| False Positive Rate | < 8% |
| Security Vulnerability Detection | OWASP Top 10 coverage |
| Category | Checks | Severity |
|---|---|---|
| Security | SQL injection, XSS, CSRF, hardcoded secrets, insecure deserialization | Critical |
| Bugs | Null pointer dereference, race conditions, resource leaks, off-by-one errors | High |
| Performance | N+1 queries, unnecessary allocations, blocking I/O, missing indexes | Medium |
| Style | Naming conventions, function length, cyclomatic complexity, dead code | Low |
| Architecture | SOLID principles, dependency injection, separation of concerns | Medium |
| Testing | Test coverage gaps, missing edge cases, assertion quality | Medium |
# .github/workflows/ai-review.yml
name: AI Code Review
on: [pull_request]
jobs:
review:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: industryai/code-review-agent@v2
with:
api-key: ${{ secrets.REVIEW_AGENT_KEY }}
severity-threshold: medium
auto-approve: false
languages: python,typescript
custom-rules: .review-rules.yml
| Setting | Default | Description |
|---|---|---|
| severity-threshold | medium | Minimum severity to report |
| auto-approve | false | Auto-approve PRs with no issues |
| max-files | 50 | Max files to review per PR |
| ignore-patterns | *.test.*, *.spec.* | Files to skip |
| custom-rules | none | Path to team-specific rules |
## AI Code Review Summary
**Files reviewed:** 8 | **Issues found:** 3 | **Suggestions:** 5
### Critical Issues
**[SECURITY] SQL Injection in user_search.py:42**
The query uses string formatting instead of parameterized queries:
```python
# Current (vulnerable)
cursor.execute(f"SELECT * FROM users WHERE name = '{name}'")
# Suggested fix
cursor.execute("SELECT * FROM users WHERE name = %s", [name])
```
### Performance Issues
**[PERF] N+1 Query in views.py:128**
The loop fetches related objects individually. Use `select_related()`:
```python
# Current (N+1 queries)
for order in Order.objects.all():
print(order.customer.name)
# Suggested fix
for order in Order.objects.select_related('customer'):
print(order.customer.name)
```
### Suggestions
- Consider adding type hints to `process_data()` (line 67)
- Function `handle_request` has cyclomatic complexity of 12 (threshold: 10)