code-agent-review
v1.0.4
Published
AI-powered code review CLI using Gemini
Maintainers
Readme
code-agent-review
An AI-powered code review CLI that uses an agent loop to read your codebase and output structured reviews covering bugs, suggestions, and security concerns.
Built with TypeScript, Vercel AI SDK, and Gemini 2.5 Flash.
Installation
npm install -g code-agent-reviewSet your Gemini API key:
export GOOGLE_GENERATIVE_AI_API_KEY=your-key-hereUsage
Review a single file
code-agent-review src/index.tsReview staged changes as a diff
code-agent-review --stagedReview each staged file individually
code-agent-review --staged-filesReview a specific commit or branch diff
code-agent-review --diff HEAD~1
code-agent-review --diff main...feat/my-branchInstall as a pre-commit hook
code-agent-review --install-hookOnce installed, the agent runs automatically on every commit and blocks it if critical issues are found.
Configuration
Create a .reviewrc.json in your project root to customise behaviour:
{
"model": "gemini-2.5-flash",
"ignore": ["dist/**", "**/*.test.ts"],
"focus": ["security", "performance"],
"maxSteps": 10
}| Option | Default | Description |
|--------|---------|-------------|
| model | gemini-2.5-flash | Gemini model to use |
| ignore | [] | Glob patterns for files to skip |
| focus | [] | Areas to focus the review on |
| maxSteps | 10 | Max agent loop steps |
Output
Findings are grouped by category and sorted by severity:
🔍 Code Review
🐛 Bugs: 🔴 CRITICAL (line 23) — SQL query constructed from unsanitised input
💡 Suggestions: 🟡 WARNING (line 45) — Consider extracting this logic into a helper function 🔵 INFO (line 12) — Unused import
🔒 Security Concerns: 🔴 CRITICAL (line 23) — Potential SQL injection vulnerability
📝 Summary: The file has a critical SQL injection vulnerability on line 23...
Security
- File system access is sandboxed to the project directory via path validation
- Git refs are validated against a whitelist before execution
- Prompt injection mitigations are in place for diff and file content
- All tools are read-only — the agent can never modify or delete files
Requirements
- Node.js >= 22
- A Gemini API key from Google AI Studio
Troubleshooting
Homebrew users — command not found after install
If you installed Node.js via Homebrew and get zsh: command not found after installing, manually symlink the binary:
ln -sf /opt/homebrew/lib/node_modules/code-agent-review/dist/index.js /opt/homebrew/bin/code-agent-review
chmod +x /opt/homebrew/lib/node_modules/code-agent-review/dist/index.jsLicense
MIT
