npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

code-agent-review

v1.0.4

Published

AI-powered code review CLI using Gemini

Readme

code-agent-review

An AI-powered code review CLI that uses an agent loop to read your codebase and output structured reviews covering bugs, suggestions, and security concerns.

Built with TypeScript, Vercel AI SDK, and Gemini 2.5 Flash.

Installation

npm install -g code-agent-review

Set your Gemini API key:

export GOOGLE_GENERATIVE_AI_API_KEY=your-key-here

Usage

Review a single file

code-agent-review src/index.ts

Review staged changes as a diff

code-agent-review --staged

Review each staged file individually

code-agent-review --staged-files

Review a specific commit or branch diff

code-agent-review --diff HEAD~1
code-agent-review --diff main...feat/my-branch

Install as a pre-commit hook

code-agent-review --install-hook

Once installed, the agent runs automatically on every commit and blocks it if critical issues are found.

Configuration

Create a .reviewrc.json in your project root to customise behaviour:

{
  "model": "gemini-2.5-flash",
  "ignore": ["dist/**", "**/*.test.ts"],
  "focus": ["security", "performance"],
  "maxSteps": 10
}

| Option | Default | Description | |--------|---------|-------------| | model | gemini-2.5-flash | Gemini model to use | | ignore | [] | Glob patterns for files to skip | | focus | [] | Areas to focus the review on | | maxSteps | 10 | Max agent loop steps |

Output

Findings are grouped by category and sorted by severity:

🔍 Code Review

🐛 Bugs: 🔴 CRITICAL (line 23) — SQL query constructed from unsanitised input

💡 Suggestions: 🟡 WARNING (line 45) — Consider extracting this logic into a helper function 🔵 INFO (line 12) — Unused import

🔒 Security Concerns: 🔴 CRITICAL (line 23) — Potential SQL injection vulnerability

📝 Summary: The file has a critical SQL injection vulnerability on line 23...

Security

  • File system access is sandboxed to the project directory via path validation
  • Git refs are validated against a whitelist before execution
  • Prompt injection mitigations are in place for diff and file content
  • All tools are read-only — the agent can never modify or delete files

Requirements

Troubleshooting

Homebrew users — command not found after install

If you installed Node.js via Homebrew and get zsh: command not found after installing, manually symlink the binary:

ln -sf /opt/homebrew/lib/node_modules/code-agent-review/dist/index.js /opt/homebrew/bin/code-agent-review
chmod +x /opt/homebrew/lib/node_modules/code-agent-review/dist/index.js

License

MIT