Toolbox/Coding agents

Code review agents

agentic code and PR review

16 repositories, most starred first
State of the category

The-PR-Agent/pr-agent The-PR-Agent/pr-agent leads the category by adoption and broad, self‑hostable PR review capabilities; pick it if you want a battle-tested, community-maintained, configurable PR reviewer you can run yourself. Before choosing, decide whether you need specialized capabilities — e.g., deep security scanning, fully local/BYOK operation, interactive review UIs, or traceable evidence — because many projects exist to cover those narrower needs.

Security tooling
Teams with real risk exposure need focused scanners and exploit‑aware pipelines that find, validate, and dedupe vulnerabilities rather than generic style or summary checks.
Self-hosting & BYOK
Organizations that must keep code and prompts on-prem or control model billing choose projects built for fully local runs, BYOK, or zero-retention client-side review.
Interactive review UIs
Developers who want to annotate plans, diffs and in‑PR Q&A need browser/IDE surfaces that let humans and agents exchange structured feedback instead of only bot comments.
Agent orchestration
Teams building complex workflows need extendable agent loops and higher‑order orchestrators to chain skills, validate outputs, and integrate external tools reliably.
Traceable verification
Safety‑conscious teams want claim-by-claim evidence, reproducible PoCs, and lightweight CI actions that produce auditable, file‑line proof rather than opaque summaries.
Find your fit

Which one matches your setup?

Answer any of the questions — the shortlist updates as you go. Recommendations come from the capability passports below, nothing else.

Where should reviews happen?
Can code leave your infrastructure?
What matters most?
Model access?
Pick at least one answer to get a shortlist.
Side by side

Comparison matrix

Axes are extracted from each project's docs by our review pipeline; the maturity score is computed from stars, growth and commit activity — not an opinion. Click a column to sort.

Runs inModelsContextCost to run
12.8k +104/7d
GitHub ActionCLIWeb appPR botBYOKOpenAIAnthropicFixed providerPR + related filesConfigurable promptsSelf-hostableUses your API key (OpenAI/other providers)
8.4k +273/7d
CLIIDECoding-agent pluginWeb appOpenAIAnthropicGeminiFixed providerDiff-focusedNo noise controlsSelf-hostableFree, self-hosted; external agent API keys or accounts may be required
7.9k +60/7d
CLICIPR botBYOKOpenAIAnthropicWhole-repo analysisRevalidate + matchersCloud APIs with keyUses your model API keys; full-repo scans can be costly for large repos
2.5k +7/7d
PR botGitHub ActionCICLIWeb appBYOKOpenAIAnthropicFixed providerRepo explorationConfigurable filtersAPI-key cloudYour API key, per-PR
919 +139/7d
CLICoding-agent pluginCIPR botBYOKGeminiWhole-repo analysisDedupe & filtersSelf-hostableYour API key; model/compute costs apply.
4.5k
PR botGitHub ActionCLICIBYOKDiff/patch onlyBasic filters/configSelf-hostableYour API key, per-PR
2.1k +37/7d
CLIWeb appBYOKOpenAIAnthropicWhole-repo analysisDeduplication & rankingSelf-hosted (cloud models)Requires model API key (your provider's billing applies).
1.4k +19/7d
PR botGitHub ActionCICLIWeb appCoding-agent pluginBYOKOpenAIAnthropicGeminiOllama / localRepo + related filesSeverity & trackingFully localYou pay your model provider (BYOK); Kodus Cloud has paid plans / self-hosting option
1.2k +20/7d
CLICoding-agent pluginBYOKDiff onlyRule-based gatesCloud API (BYOK)Your model API key / agent usage fees
432 +4/7d
PR botGitHub ActionCICLIBYOKOpenAIAnthropicGeminiOllama / localDiff + related filesSeverity & filtersCan run fully localUses your LLM API key (your provider's billing applies)
159
CLIIDECoding-agent pluginOpenAIAnthropicFixed providerWhole-repo analysisDeduplication & intakeCan run fully localUses your coding agent (no separate model API key); optional hosted dashboard sync
117 +1/7d
PR botGitHub ActionCICLIIDECoding-agent pluginWeb appBYOKOpenAIAnthropicGeminiOllama / localDiff + related filesSeverity gatingCan run fully localYour API key for cloud models, or local compute costs
Ranked by maturity — 4 more in the full catalog below.
At a glance

Capability profiles

Six axes, 0–5 each. The shape tells you the strategy: a wide hexagon is a generalist, a spike is a specialist. Showing the 8 most established — the rest are in the full catalog.

ContextNoiseCustomPrivacyModelsMaturity

An open-source, community-maintained, self‑hostable PR reviewer that compresses and adapts PR context and exposes JSON-configurable prompts for team customization.

ContextNoiseCustomPrivacyModelsMaturity

A local, browser-based review surface that plugs directly into many agent hooks so you can annotate plans, diffs, and HTML and send structured feedback back to the agent.

ContextNoiseCustomPrivacyModelsMaturity

Agent-powered whole-repo vulnerability scanner that scales across workers, resumes interrupted runs, and lets you grow project-specific matchers.

ContextNoiseCustomPrivacyModelsMaturity

Provides an extendable agent loop built on flue/pi with Model Context Protocol (MCP) support to explore the repo using real developer tools and integrate external tools.

ContextNoiseCustomPrivacyModelsMaturity

A modular, stack-agnostic suite of security review skills that lets coding agents find, reproduce, dedupe, and patch vulnerabilities with sandboxed execution and a sequential pipeline.

ContextNoiseCustomPrivacyModelsMaturity

Provides a GitHub App and Action that runs ChatGPT/LLM-based reviews and supports GitHub models, Azure/OpenAI endpoints, and self-hosting.

ContextNoiseCustomPrivacyModelsMaturity

Orchestrates focused AI agent workflows in disposable job containers to find, validate and de-duplicate real vulnerabilities with PoC generation and ranking.

ContextNoiseCustomPrivacyModelsMaturity

Model-agnostic, BYOK AI code review with plain-language Kody Rules and self-hosting to avoid LLM cost markups and maintain full control over data.

All repositories (16)

🚀 PR Agent: The Original Open-Source PR Reviewer. This project is not the Qodo free tier.

12.8k
+1047d
Python
3 yrs

Annotate and review coding agent plans and code diffs visually, share with your team, send feedback to agents…

8.4k
+2737d
TypeScript
8 mo

Deepsec is a security harness for finding vulnerabilities in your codebase powered by coding agents

7.9k
+607d
TypeScript
4 mo

🐥 A code review bot powered by ChatGPT

4.5k
JavaScript
3 yrs

extendable code review and QA agent 🚢

2.5k
+77d
TypeScript
3 yrs

Open-source, self-hosted AI vulnerability research tool that orchestrates agents to find and validate security…

2.1k
+377d
JavaScript
1 mo

AI Code Review with Full Control Over Model Choice and Costs.

1.4k
+197d
TypeScript
1 yr

Guard skills for coding agents, quality gates that catch AI-generated failure modes in code, tests, and docs

1.2k
+207d
3 mo

AI Code Reviewer: Enhance your GitHub workflow with AI-powered code review! Get intelligent feedback and sugge…

1.0k
-17d
TypeScript
3 yrs

A modular, stack-agnostic toolkit of security review skills for AI coding agents to autonomously find, reprodu…

919
+1397d
Python
2 mo

An AI-powered GitHub code review tool that uses LLMs to detect high-confidence, high-impact issues—such as sec…

432
+47d
Python
1 yr

Context-aware AI reviewer for Pull Requests. Instant summary, line-by-line comments, title generation and more

187
TypeScript
1 yr

Security testing that runs inside the coding agent you already use. Source-available, not open source.

159
TypeScript
2 wk

AI Coding Agent Orchestrator 2026: Pro-Level Strategy & Review Framework

117
+17d
HTML
2 mo

Vetix — Automated scanning, identification, and assessment of SKILL security risks.

61
Python
3 mo

AI code review with DeepSeek: headless PR review automation that verifies PR descriptions claim-by-claim again…

43
+17d
Python
2 wk
Don't want to self-host?

Hosted alternatives

If running your own reviewer is more ops than you want, these managed services cover the same job.

CodeRabbit

Managed PR review bot from the team behind the once-popular open-source ai-pr-reviewer, which was retired in its favor.

Try CodeRabbit
Qodo Merge

Hosted continuation of the pr-agent lineage with org-wide config, SSO and support.

Try Qodo Merge
Greptile

Review with full-codebase context as the headline feature; strongest when your bugs are cross-file.

Try Greptile

More in Coding agents