Back to Marketplace
Code Reviewer
proAvailableSecurity-focused code review with sandboxed execution
Reviews pull requests, identifies security vulnerabilities, suggests fixes, and runs test suites in a sandboxed Docker environment. 6-layer sandbox isolation prevents malicious code execution.
Overview
Code Reviewer is a single-LLM agent that performs automated code reviews with security focus. It doesn't just lint — it understands the code, identifies vulnerabilities, and suggests fixes with working code examples.
How It Works
- Connect your GitHub repository
- The agent reviews each pull request automatically
- It identifies security issues, performance problems, and style violations
- It runs your test suite in a sandboxed Docker environment
- It posts review comments with suggested fixes
Governance
- Hardened sandboxing — submitted code runs in Docker with 6 security layers
- TPNN defense — malicious PRs can't inject prompts into the review
- Audit receipts — every review is cryptographically signed
- MCP tools — GitHub, Docker, and test runner access via declarative protocol
Use Cases
- Automated PR reviews for small teams
- Security audits for open-source projects
- Pre-merge quality gates in CI/CD
- Onboarding new developers with consistent review standards
Capabilities
- Security vulnerability detection
- Performance issue identification
- Automated test execution in sandbox
- PR review comments with suggested fixes
- Multi-language support (Rust, TS, Python, Go)
Tools (MCP Protocol)
github_apidocker_exectest_runnerlint_runnerGovernance Layers
Hardened SandboxTPNN DefenseJWT AuthAudit ReceiptsMCP ToolsSIEM Integration