No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by bobmatnyc · Agent Tool · ★ 55
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is ai-code-review safe to install? View the security audit →
AI Code Review v4.6.9 [!WARNING] This project is archived as of 2026-05-19. No further updates will be released. AI Code Review has been succeeded by trusty-analyze — a deterministic static analysis daemon (Rust) that delivers reproducible results, zero API cost, and sub-millisecond query latency. This repository and the npm package remain available for cloning, downloading, and continued local use. Issues and pull requests are closed. See DEPRECATED.md for the full announcement, a detailed feature comparison, and a migration guide. A TypeScript-based tool for automated code reviews using Google's Gemini AI models, Anthropic Claude models (including Claude 4), OpenAI models, and OpenRouter API with LangChain integration for enhanced prompt management.
| Stars | 55 |
| Forks | 7 |
| Language | TypeScript |
| Category | Agent Tool |
| License | MIT |
| Quality Score | 64.2686141167506/100 |
| Last Updated | 2026-05-20 |
| Created | 2025-04-05 |
| Platforms | claude-code, cli, gemini, node |
| Est. Tokens | ~2788k |
These tools work well together with ai-code-review for enhanced workflows:
Explore other popular agent tool tools:
ai-code-review is AI-powered code review CLI with multiple providers (Gemini, Claude, OpenAI). Features 95%+ token reduction via semantic chunking, 7 review types (security/performance/evaluation), multi-language suppo. It is categorized as a Agent Tool with 55 GitHub stars.
ai-code-review is primarily written in TypeScript.
You can find installation instructions and usage details in the ai-code-review GitHub repository at github.com/bobmatnyc/ai-code-review. The project has 55 stars and 7 forks, indicating an active community.
ai-code-review is released under the MIT license, making it free to use and modify according to the license terms.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: