AI-powered code review that analyzes PRs for bugs, security vulnerabilities, performance issues, and style violations. Posts inline comments with severity levels and submits a review verdict.
- Identifier
code-review- Version
- 1.0.1
- Steps
- 3
- Triggers
- 2
- review
- quality
- security
- automated
When it runs
pull_request.opened- Settle delay
- 60s after the event
Only when all hold
- pullRequest.isDraft not equals true
- actor.username not contains [bot]
pull_request.synchronize- Settle delay
- 90s after the event
Only when all hold
- pullRequest.isDraft not equals true
- actor.username not contains [bot]
The pipeline
The graph below is the one the workflow opens with in the builder — same steps, same layout, drawn on the same canvas. The run playing through it is a simulation; the branches and conditions are real.
- 01PR Opened / Updated
triggerThe event that starts the run.
- 02Clone Repository
git.cloneShallow-clones the repository at the right ref.
- 03AI Code Review
agent.runOne agent works the task with its toolkit.
The agent
PR Code Reviewer
- Base type
- Code Reviewer
- Temperature
- 0.2
- Max iterations
- 30
- Tools
- 6
Git provider · 3
get_pull_request_diffGet Pull Request Diff · readadd_pull_request_review_threadAdd PR Review Thread · writesubmit_reviewSubmit Review · write
Filesystem · 2
read_fileRead File · readlist_dirList Directory · read
Code search · 1
code_searchCode Search · read
Related playbooks
Accessibility Audit
Reviews UI PRs for accessibility defects, posts inline threads citing WCAG criteria, and submits a summary review.
API Contract Breaking-Change Detector
Detects breaking changes in published API contracts, names affected consumers, and labels the PR.
Dark Mode Audit
Reviews style changes for colors that render one theme's text on the other theme's background and checks both themes define every new token.