Code review agents
agentic code and PR review
The-PR-Agent/pr-agent The-PR-Agent/pr-agent leads the category by adoption and broad, self‑hostable PR review capabilities; pick it if you want a battle-tested, community-maintained, configurable PR reviewer you can run yourself. Before choosing, decide whether you need specialized capabilities — e.g., deep security scanning, fully local/BYOK operation, interactive review UIs, or traceable evidence — because many projects exist to cover those narrower needs.
Which one matches your setup?
Answer any of the questions — the shortlist updates as you go. Recommendations come from the capability passports below, nothing else.
Comparison matrix
Axes are extracted from each project's docs by our review pipeline; the maturity score is computed from stars, growth and commit activity — not an opinion. Click a column to sort.
| Runs in | Models | Context | Cost to run | |||||
|---|---|---|---|---|---|---|---|---|
⭐ 12.8k +104/7d | GitHub ActionCLIWeb appPR bot | BYOKOpenAIAnthropicFixed provider | PR + related files | Configurable prompts | ●●●●● | Self-hostable | ●●●●● | Uses your API key (OpenAI/other providers) |
⭐ 8.4k +273/7d | CLIIDECoding-agent pluginWeb app | OpenAIAnthropicGeminiFixed provider | Diff-focused | No noise controls | ●●●●● | Self-hostable | ●●●●● | Free, self-hosted; external agent API keys or accounts may be required |
⭐ 7.9k +60/7d | CLICIPR bot | BYOKOpenAIAnthropic | Whole-repo analysis | Revalidate + matchers | ●●●●● | Cloud APIs with key | ●●●●● | Uses your model API keys; full-repo scans can be costly for large repos |
⭐ 2.5k +7/7d | PR botGitHub ActionCICLIWeb app | BYOKOpenAIAnthropicFixed provider | Repo exploration | Configurable filters | ●●●●● | API-key cloud | ●●●●● | Your API key, per-PR |
⭐ 919 +139/7d | CLICoding-agent pluginCIPR bot | BYOKGemini | Whole-repo analysis | Dedupe & filters | ●●●●● | Self-hostable | ●●●●● | Your API key; model/compute costs apply. |
⭐ 4.5k | PR botGitHub ActionCLICI | BYOK | Diff/patch only | Basic filters/config | ●●●●● | Self-hostable | ●●●●● | Your API key, per-PR |
⭐ 2.1k +37/7d | CLIWeb app | BYOKOpenAIAnthropic | Whole-repo analysis | Deduplication & ranking | ●●●●● | Self-hosted (cloud models) | ●●●●● | Requires model API key (your provider's billing applies). |
⭐ 1.4k +19/7d | PR botGitHub ActionCICLIWeb appCoding-agent plugin | BYOKOpenAIAnthropicGeminiOllama / local | Repo + related files | Severity & tracking | ●●●●● | Fully local | ●●●●● | You pay your model provider (BYOK); Kodus Cloud has paid plans / self-hosting option |
⭐ 1.2k +20/7d | CLICoding-agent plugin | BYOK | Diff only | Rule-based gates | ●●●●● | Cloud API (BYOK) | ●●●●● | Your model API key / agent usage fees |
⭐ 432 +4/7d | PR botGitHub ActionCICLI | BYOKOpenAIAnthropicGeminiOllama / local | Diff + related files | Severity & filters | ●●●●● | Can run fully local | ●●●●● | Uses your LLM API key (your provider's billing applies) |
⭐ 159 | CLIIDECoding-agent plugin | OpenAIAnthropicFixed provider | Whole-repo analysis | Deduplication & intake | ●●●●● | Can run fully local | ●●●●● | Uses your coding agent (no separate model API key); optional hosted dashboard sync |
⭐ 117 +1/7d | PR botGitHub ActionCICLIIDECoding-agent pluginWeb app | BYOKOpenAIAnthropicGeminiOllama / local | Diff + related files | Severity gating | ●●●●● | Can run fully local | ●●●●● | Your API key for cloud models, or local compute costs |
Capability profiles
Six axes, 0–5 each. The shape tells you the strategy: a wide hexagon is a generalist, a spike is a specialist. Showing the 8 most established — the rest are in the full catalog.
An open-source, community-maintained, self‑hostable PR reviewer that compresses and adapts PR context and exposes JSON-configurable prompts for team customization.
A local, browser-based review surface that plugs directly into many agent hooks so you can annotate plans, diffs, and HTML and send structured feedback back to the agent.
Agent-powered whole-repo vulnerability scanner that scales across workers, resumes interrupted runs, and lets you grow project-specific matchers.
Provides an extendable agent loop built on flue/pi with Model Context Protocol (MCP) support to explore the repo using real developer tools and integrate external tools.
A modular, stack-agnostic suite of security review skills that lets coding agents find, reproduce, dedupe, and patch vulnerabilities with sandboxed execution and a sequential pipeline.
Provides a GitHub App and Action that runs ChatGPT/LLM-based reviews and supports GitHub models, Azure/OpenAI endpoints, and self-hosting.
Orchestrates focused AI agent workflows in disposable job containers to find, validate and de-duplicate real vulnerabilities with PoC generation and ranking.
Model-agnostic, BYOK AI code review with plain-language Kody Rules and self-hosting to avoid LLM cost markups and maintain full control over data.
All repositories (16)
🚀 PR Agent: The Original Open-Source PR Reviewer. This project is not the Qodo free tier.
Annotate and review coding agent plans and code diffs visually, share with your team, send feedback to agents…
Deepsec is a security harness for finding vulnerabilities in your codebase powered by coding agents
Open-source, self-hosted AI vulnerability research tool that orchestrates agents to find and validate security…
AI Code Review with Full Control Over Model Choice and Costs.
Guard skills for coding agents, quality gates that catch AI-generated failure modes in code, tests, and docs
AI Code Reviewer: Enhance your GitHub workflow with AI-powered code review! Get intelligent feedback and sugge…
A modular, stack-agnostic toolkit of security review skills for AI coding agents to autonomously find, reprodu…
An AI-powered GitHub code review tool that uses LLMs to detect high-confidence, high-impact issues—such as sec…
Context-aware AI reviewer for Pull Requests. Instant summary, line-by-line comments, title generation and more
Security testing that runs inside the coding agent you already use. Source-available, not open source.
AI Coding Agent Orchestrator 2026: Pro-Level Strategy & Review Framework
Vetix — Automated scanning, identification, and assessment of SKILL security risks.
AI code review with DeepSeek: headless PR review automation that verifies PR descriptions claim-by-claim again…
Hosted alternatives
If running your own reviewer is more ops than you want, these managed services cover the same job.
Managed PR review bot from the team behind the once-popular open-source ai-pr-reviewer, which was retired in its favor.
Try CodeRabbit →Hosted continuation of the pr-agent lineage with org-wide config, SSO and support.
Try Qodo Merge →Review with full-codebase context as the headline feature; strongest when your bugs are cross-file.
Try Greptile →