ai-code-review — security grade SAFE, quality 64/100

Security audit verdict: SAFE · quality 64/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by bobmatnyc · Agent Tool · ★ 55

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is ai-code-review safe to install? View the security audit →

About ai-code-review

AI Code Review v4.6.9 [!WARNING] This project is archived as of 2026-05-19. No further updates will be released. AI Code Review has been succeeded by trusty-analyze — a deterministic static analysis daemon (Rust) that delivers reproducible results, zero API cost, and sub-millisecond query latency. This repository and the npm package remain available for cloning, downloading, and continued local use. Issues and pull requests are closed. See DEPRECATED.md for the full announcement, a detailed feature comparison, and a migration guide. A TypeScript-based tool for automated code reviews using Google's Gemini AI models, Anthropic Claude models (including Claude 4), OpenAI models, and OpenRouter API with LangChain integration for enhanced prompt management.

Quick Facts

Stars55
Forks7
LanguageTypeScript
CategoryAgent Tool
LicenseMIT
Quality Score64.2686141167506/100
Last Updated2026-05-20
Created2025-04-05
Platformsclaude-code, cli, gemini, node
Est. Tokens~2788k

Compatible Skills

These tools work well together with ai-code-review for enhanced workflows:

  • open-code-review — semantic(0.24)+complementary+same_lang+similar_pop+shared_platform (53%)
  • token-optimizer-mcp — semantic(0.21)+complementary+same_lang+similar_pop+shared_platform (52%)

More Agent Tool Tools

Explore other popular agent tool tools:

View all Agent Tool tools →

Popular TypeScript Agent Tools

Frequently Asked Questions

What is ai-code-review?

ai-code-review is AI-powered code review CLI with multiple providers (Gemini, Claude, OpenAI). Features 95%+ token reduction via semantic chunking, 7 review types (security/performance/evaluation), multi-language suppo. It is categorized as a Agent Tool with 55 GitHub stars.

What programming language is ai-code-review written in?

ai-code-review is primarily written in TypeScript.

How do I install or use ai-code-review?

You can find installation instructions and usage details in the ai-code-review GitHub repository at github.com/bobmatnyc/ai-code-review. The project has 55 stars and 7 forks, indicating an active community.

What license does ai-code-review use?

ai-code-review is released under the MIT license, making it free to use and modify according to the license terms.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse Agent Tool tools