Inspiration
Manual code review means checking the code AND separately searching for known CVEs, community bug reports, and recent security releases — usually across 3-4 different tabs. We wanted one tool that does both, together.
What it does
CodeReview Agent analyzes any public GitHub repo for security vulnerabilities, performance issues, code quality, test coverage, and dependency risk. What makes it different: it pulls live web intelligence via SerpApi (real-time CVEs, community issues, recent news) at analysis time, then has the model explicitly reason about whether a found vulnerability actually applies to this repo's current dependencies — not a generic list.
Every issue comes with a file path, line number, a confidence level (so it's honest about uncertainty), and a one-click fix. Past reviews are embedded and stored so recurring patterns get flagged automatically across repos.
How we built it
- Next.js + TypeScript frontend/backend
- Groq for fast LLM inference on the review + synthesis step
- SerpApi for live CVE/community/news lookups, run concurrently with the repo analysis
- Supabase (Postgres + pgvector) for auth, rate limiting, and storing review embeddings for agentic memory
- AWS S3 for optional artifact storage, AWS Bedrock explored for embeddings fallback
Challenges we ran into
Getting the model to actually connect a live CVE to the specific repo's dependency version — instead of just listing unrelated CVEs — took careful prompt design in the synthesis step.
Accomplishments
Real-time, grounded findings (not hallucinated CVEs), confidence-scored issues, and a working agentic memory layer that recalls similar past reviews.
What's next
Support for private repos, more package ecosystems, and CI integration.
Built With
- amazon-web-services
- bedrock
- community-bug-reports
- css
- groq
- next.js
- performance-issues
- pgvector
- postgresql
- react
- s3
- serpapi
- supabase
- tailwind
- typescript
Log in or sign up for Devpost to join the conversation.