Find the top AI-powered code review tools that help you catch bugs, enforce style, and improve code quality automatically.
Code Review tools are AI-powered software designed to help developers and teams tackle code review-related tasks more efficiently. These tools are typically published as open-source projects on GitHub and can be integrated into existing workflows via MCP (Model Context Protocol), Claude Skills, or standalone agent frameworks. On Agent Skills Hub, we index 66 quality-scored code review tools across languages including Go, JavaScript, Python.
In 2026, the AI agent ecosystem is maturing rapidly. Code Review tools can significantly boost development efficiency by automating repetitive tasks, reducing human error, and providing intelligent suggestions. The top 3 tools — open-code-review, codex-plugin-cc, code-review-graph — have earned an average of 2,191 GitHub stars, reflecting strong community validation. 55 of the listed tools come with clear open-source licenses, ensuring freedom to use and modify.
When choosing a code review tool, consider these factors: 1) Community activity — GitHub stars and recent commit frequency indicate reliability; 2) Integration method — check if it supports MCP, Claude, or your preferred agent framework; 3) Language compatibility — the most common language in this list is Go; 4) Quality score — Agent Skills Hub's composite score evaluates code quality, documentation completeness, and maintenance activity. Our recommendation: start with open-code-review — it ranks highest in both star count and quality score.
Secure, fast, efficient, battle-tested at Alibaba's scale. Hybrid architecture code review tool: deterministic pipelines + LLM Agent, precise line-level comments, built-in multi-language ruleset (NPE, thread-safety, XSS, SQL injection), OpenAI & Anthropic compatible.
Use Codex from Claude Code to review code or delegate tasks.
Local-first code intelligence graph for MCP and CLI. Builds a persistent map of your codebase so AI coding tools read only what matters, with benchmarked context reductions on reviews and large-repo workflows.
🚀 PR Agent: The Original Open-Source PR Reviewer. This project is not the Qodo free tier.
An AI-powered security review GitHub Action using Claude to analyze code changes for security vulnerabilities.
A comprehensive code review skill for Claude Code, covering React 19, Vue 3, Rust, TypeScript, TanStack Query v5, and more.
AI code reviews grounded in 12 classic engineering books — decay risk diagnostics with book citations, severity labels, and 6 analysis modes including full-sweep auto-fix
Guard skills for coding agents, quality gates that catch AI-generated failure modes in code, tests, and docs
```bash
npx skills add amElnagdy/guard-skills --list
```
Review your coding agent's diff in a terminal pane and send line comments back to Claude Code, Codex, OpenCode or Pi. A herdr plugin.
A staged code-review workflow and local dashboard built with TypeSafe Jev.
🚀 AI-powered code review tool for GitHub, GitLab, Bitbucket Cloud, Bitbucket Server, Azure DevOps and Gitea — built with LLMs like OpenAI, Claude, Gemini, Ollama, Bedrock, OpenRouter and Azure OpenAI
Multi-LLM peer review for code decisions. Bring your own CLI; Chorus convenes 2-4 other LLMs to review the work before you ship.
Local AI PR workbench — Claude/Codex review in isolated git worktrees, human-gated GitHub comments
Adversarial AI bug hunter with auto-fix skill for Claude Code, Cursor, Codex CLI, GitHub Copilot CLI, Kiro CLI, Opencode, Pi Coding Agent, and more. Multi-agent pipeline finds security vulnerabilities, logic errors, and runtime bugs — then fixes them autonomously on a safe branch.
Open-source Agentic code review tool inspired by DevinReview, using Recursive Language Models (RLM)
An AI-powered GitHub code review tool that uses LLMs to detect high-confidence, high-impact issues—such as security vulnerabilities, bugs, and maintainability concerns.
Agent skill for checking PR review comments, status checks, and description completeness
AI-powered multi-agent code review. Simulates a customizable team of Engineers performing code review with built-in discourse.
Multi-lens code audit tool — 280 expert AI agents for code review, security testing, and infrastructure auditing
Security scanning skill for Claude Code, Codex and Antigravity. Finds the 21 most common vulnerabilities in AI-written code and shows how to fix each one.
Local-first MCP plugin for continuous software-quality review by AI coding agents, powered by Jev.
review-forge is an Agent Skill for structured, auditable code review workflows
AI-powered cybersecurity code review skill for Claude Code. 8 specialist agents, OWASP 2025, CWE Top 25, MITRE ATT&CK, 11 languages, zero configuration.
Entity-level code review for Git. Graph-based risk scoring, change classification, commit untangling. 95% recall on the Greptile benchmark.
Context-aware AI reviewer for Pull Requests. Instant summary, line-by-line comments, title generation and more
A local code review tool designed for the coding agent workflow
```bash
npm install -g diffx-cli
```
Subagent Verification for Claude AI Code Networks 2026
Cheaper and better Greptile alternative runs on your own github actions.
Agentic code reviewer for GitHub PRs and GitLab MRs. Multi-step reasoning with autonomous tool orchestration — catches bugs requiring analysis across files.
```bash
# Just run it (zero install, always latest)
npx @mrkaran/hodor <PR_URL>
# Or install globally
npm install -g @mrkaran/hodor
```
codexqa: 11 local-first Agent Skills for Cursor, Claude Code, Codex & OpenClaw — change impact analysis, AI code review, defect scan, testcase generation, browser replay & RCA.
Review behavior, not just diffs. Jev prioritizes human attention; OpenAI explains the changes. Local CLI + agent skill + GitHub extension.
Brutally honest senior-engineer code reviews for Claude Code, Cursor & Windsurf - and your terminal. Scores, evidence-backed issues, usable fixes.
A practical example of integrating AI code review into a real-world codebase. Built with Next.js and Firebase, this repo highlights structured prompts, reusable review skills, and parallel subagent execution via Claude Code and OpenAI Codex.
Claude Code skill for reviewing and designing code based on Clean Architecture principles (Dependency Rule, Layer Structure, SOLID)
AI-powered code quality analysis using MCP to help AI assistants review code more effectively. Analyze git changes for complexity, security issues, and more through structured prompts.
学习 learn-claude-code 后的 PR Review Agent 实践项目:构建 Debate Council 多 Agent 审查、Tool Calling、结构化报告与 AI Judge 评估。
Evidence-based code review skills for Codex and Claude Code
Knowledge graph for token-efficient code reviews -- semantic search and call-graph resolution across your codebase.
Knowledge graph for token-efficient code reviews -- semantic search and call-graph resolution across your codebase.
Free, AI PR reviewer that runs entirely in GitHub Actions. No hosting required.
Local AI pull request reviewer — review GitHub and BitBucket PRs right from your terminal, powered by the Claude Code, Gemini, and Codex CLIs.
Read what your agent wrote before you say LGTM. A fast TUI in Zig for reviewing code with vim motions.
Multi-agent codebase review for PRs, CI, and downstream fork syncs.
Ghost personas review your code before it ships. Find edge cases, race conditions, and business logic bugs before production.
AI-powered code review CLI with multiple providers (Gemini, Claude, OpenAI). Features 95%+ token reduction via semantic chunking, 7 review types (security/performance/evaluation), multi-language support, interactive fixes, and developer skill assessment.
Open source Claude skill for automated GitLab MR reviews. Configurable lint rules, semantic analysis, and inline comment posting for self-hosted GitLab instances.
A native /slop-review window for Claude Code, Codex CLI, and pi — review the slop before you ship it. Monaco-powered inline comments, agent reads them back. Forked from badlogic/pi-diff-review.
🔍 Agent Verifier is a coding agent skill that verifies code against organizational policies, code quality patterns, security requirements, and framework best practices — before code ships. Works with Claude Code, Cursor, Windsurf, and 30+ agents.
Comprehensive multi-agent code review for Claude Code
Context-Driven Development plugin for Claude Code, Cursor, GitHub Copilot, Gemini
Local, live code review for the AI age - read what the agent wrote and send feedback straight back
Local-first multi-runtime AI cockpit (CLI + desktop + MCP). War-rooms across Claude/Codex/Gemini, replay, regression detection, receipts in SQLite. MIT.
Review-only AI code review for GitHub pull requests. Cross-check PRs with model-agnostic reviewers that can comment inline but cannot approve, merge, or close.
MCP server for AI-to-AI collaboration — bridge Claude with Gemini, Codex, and other LLMs for code review, second opinions, and plan debate
🤖 AI code quality gate for AI-generated code. Detects hallucinated packages, phantom dependencies, stale APIs, and more. MCP Server + CLI + CI/CD Action.
使用 TypeSafe Jev 审查 Skill 与 MCP 可疑行为 | Review Agent Skills and MCP code with Jev, static evidence, and explicit coverage gaps
🚦 Senior-QA review skill for Claude Code: runs a regression hunter + a change reviewer in parallel, then gives one read-only SIGN OFF / DO NOT SHIP verdict with file:line evidence.
20 AI agents in your git workflow. Secrets, injection flaws and unsafe migrations are blocked at commit; performance, coverage and the rest are reviewed at push. Research → Plan → Implement workflow with GO/NO-GO gates before you write a line. Generates production-ready code, product wikis and codebase maps on demand. Any language. Free.
Checks AI-generated code changes before merge: scope, validation, risk, review evidence, and optional Verity receipts.
Agentic code review CLI — LangGraph orchestrates 13 deterministic static analyzers (oxlint/bandit/clippy/spotbugs/golangci/cppcheck) + LLM reasoning across 23 languages including industrial PLC. Grounding validator kills hallucinated paths. RAG over your guidelines. dedup --fix actually edits files with multi-step undo (no git required).
Ask your AI questions about its own code changes — from a Git diff viewer.
OBJECTION! A skill and plugin for AI coding agents (Claude Code, Codex, Cursor, Gemini): accusers, a defender and a judge review the PR, and a gate blocks it until APPROVED.
Evidence-based review skill for diff, project, and artifact review across code, readiness, architecture, requirements, and risk.
| Tool | Stars | Language | License | Score |
|---|---|---|---|---|
| open-code-review | ★ 43.2k | Go | Apache-2.0 | 85 |
| codex-plugin-cc | ★ 33.8k | JavaScript | Apache-2.0 | 72 |
| code-review-graph | ★ 31.6k | Python | MIT | 76 |
| pr-agent | ★ 13.2k | Python | MIT | 77 |
| claude-code-security-review | ★ 6.3k | Python | MIT | 74 |
| shippie | ★ 2.5k | TypeScript | MIT | 68 |
| code-review-skill | ★ 1.9k | HTML | MIT | 75 |
| brooks-lint | ★ 1.5k | HTML | MIT | 76 |
| guard-skills | ★ 1.2k | — | MIT | 83 |
| herdr-reviewr | ★ 823 | Rust | MIT | 78 |
| jev-review | ★ 663 | TypeScript | MIT | 70 |
| ai-review | ★ 585 | Python | Apache-2.0 | 68 |
| chorus | ★ 527 | TypeScript | Apache-2.0 | 66 |
| pr-cockpit | ★ 492 | TypeScript | MIT | 65 |
| bug-hunter | ★ 487 | JavaScript | MIT | 75 |
| AsyncReview | ★ 457 | Python | MIT | 51 |
| Gito | ★ 436 | Python | MIT | 66 |
| skills | ★ 399 | — | MIT | 73 |
| open-code-review | ★ 331 | TypeScript | Apache-2.0 | 65 |
| perch | ★ 315 | JavaScript | MIT | 62 |
| RepoLens | ★ 296 | Shell | Apache-2.0 | 66 |
| vbsec | ★ 282 | Python | MIT | 73 |
| jev-review | ★ 232 | TypeScript | MIT | 67 |
| review-forge | ★ 220 | — | — | 70 |
| claude-cybersecurity | ★ 208 | Shell | MIT | 59 |
| inspect | ★ 190 | Python | — | 54 |
| ai-reviewer | ★ 187 | TypeScript | MIT | 65 |
| diffx | ★ 183 | TypeScript | — | 68 |
| agent-skills-code-review-router | ★ 125 | — | — | 53 |
| claude-ops-inspector | ★ 120 | HTML | — | 65 |
| juror | ★ 119 | TypeScript | MIT | 63 |
| hodor | ★ 111 | TypeScript | MIT | 71 |
| codexqa | ★ 111 | Python | Apache-2.0 | 61 |
| jev-code-reviewer | ★ 111 | JavaScript | MIT | 59 |
| cynical-sally | ★ 97 | TypeScript | MIT | 68 |
| fullcase-web | ★ 93 | TypeScript | — | 57 |
| clean-architecture-skills | ★ 90 | — | MIT | 79 |
| lucidity-mcp | ★ 89 | Python | Apache-2.0 | 41 |
| pr-review-agent-council | ★ 86 | Python | — | 63 |
| code-review-skills | ★ 76 | Python | MIT | 65 |
| crg | ★ 68 | Python | Apache-2.0 | 62 |
| better-code-review-graph | ★ 67 | Python | Apache-2.0 | 60 |
| openrabbit | ★ 66 | TypeScript | Apache-2.0 | 65 |
| reviewd | ★ 61 | Python | MIT | 66 |
| lgtm | ★ 61 | Zig | Apache-2.0 | 67 |
| codebase-argus | ★ 58 | TypeScript | MIT | 66 |
| simulacra | ★ 58 | — | MIT | 54 |
| ai-code-review | ★ 55 | TypeScript | MIT | 55 |
| clab | ★ 51 | Go | — | 59 |
| slop-review | ★ 47 | JavaScript | — | 69 |
| agent-verifier | ★ 44 | — | MIT | 72 |
| claude-review-all | ★ 41 | Python | MIT | 71 |
| draft | ★ 40 | HTML | MIT | 59 |
| diffo | ★ 34 | TypeScript | Apache-2.0 | 57 |
| Agentic-Tool-Optimization | ★ 33 | Rust | MIT | 56 |
| elek | ★ 19 | TypeScript | MIT | 54 |
| ask-llm | ★ 18 | TypeScript | MIT | 61 |
| open-code-review | ★ 13 | TypeScript | — | 48 |
| jev-security-scan | ★ 12 | Python | MIT | 63 |
| shipcheck | ★ 11 | Shell | MIT | 71 |
| manta | ★ 10 | Shell | — | 65 |
| agent-guardrails | ★ 8 | JavaScript | MIT | 64 |
| revio | ★ 8 | Python | Apache-2.0 | 64 |
| askdiff | ★ 7 | TypeScript | MIT | 43 |
| objection | ★ 7 | Shell | MIT | 64 |
| review-skill | ★ 1 | PowerShell | MIT | 48 |
The top code review tools in 2026 are open-code-review, codex-plugin-cc, code-review-graph. Agent Skills Hub ranks 66 options by GitHub stars, quality score (6 dimensions including completeness, examples, and agent readiness), and recent activity. The list is rebuilt every 8 hours from live GitHub data.
open-code-review (43.2k stars) is the most adopted choice for general code review workflows, written in Go. codex-plugin-cc (33.8k stars) is a strong alternative and uses JavaScript instead. Pick by your existing stack: match the language and runtime your team already uses to minimize integration cost. If unsure, start with open-code-review — it has the deepest community and the most examples online.
Avoid pre-built code review tools when (1) your use case requires deep customization that the tool's plugin system doesn't support, (2) you have strict compliance requirements that ban third-party dependencies, (3) the tool's maintenance is inactive (last commit >6 months ago), or (4) your data volume is small enough that a 50-line custom script is cheaper than learning the tool. For most production workflows above 100 requests/day, the time savings from a maintained tool outweigh the customization loss.
Code Review focuses specifically on find the top ai-powered code review tools that help you catch bugs, enforce style, and improve code quality automatically. Test Generation is a related but distinct category — see https://agentskillshub.top/best/test-generation/ for those tools. The two often appear in the same agent pipeline but solve different problems: choose code review when your primary goal is the specific task, and test generation when the workflow is broader.
For most teams, yes. open-code-review has 43.2k stars worth of community testing, handles edge cases you haven't thought of, and ships with documentation. Build your own only when (1) your requirements are deeply non-standard, (2) you have a security/compliance reason to avoid OSS dependencies, or (3) the maintenance burden is small enough (<200 lines of code) that you'll save time long-term. The break-even point is usually around 2-3 weeks of dev time saved.
Most code review tools listed are open source under permissive licenses (MIT, Apache 2.0). A handful offer paid managed/cloud versions on top of free self-hosted core. Always check the LICENSE file on each tool's GitHub repository before commercial use — some use AGPL or non-commercial restrictions that may not fit your deployment model.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: