CodeReview Sentinel — Autonomous PR Triage Agent

Code review is one of the most important yet time-consuming tasks in software development. Every PR needs careful review for complexity, risk, style, security — and review backlogs are a universal bottleneck that slows teams down.

CodeReview Sentinel solves this by running an autonomous AI agent that triages PRs the moment they're opened. Built with the Strands Agents SDK, the agent uses 6 callable tools in an autonomous reasoning loop:

  1. PERCEIVE — analyze_diff extracts complexity metrics (lines added/removed, files changed, complexity score)
  2. ANALYZE — classify_severity assesses risk level based on file patterns and dangerous code detection
  3. CHECK — check_style validates code style compliance for Python, JavaScript, TypeScript, and Go
  4. SCAN — security_scan detects 15+ vulnerability patterns (hardcoded secrets, RCE, XSS, SQLi, pickle deserialization, SSL bypass)
  5. REPORT — generate_review_comment produces a structured markdown review comment ready to post
  6. SUMMARIZE — draft_pr_summary generates a concise PR summary for maintainers

The agent autonomously decides which tools to call, in what order, and synthesizes results into a coherent, actionable review. It surfaces only what matters — risk factors, security findings, style issues — and gives a clear recommendation: auto-approve, needs review, or block merge.

Why this is a Professional Agent

Code review is a repetitive, judgment-heavy task that every developer does. CodeReview Sentinel makes developers dramatically better at it by handling the first-pass triage automatically, letting human reviewers focus on the nuanced decisions that require human judgment.

Tech Stack

  • Python + FastAPI backend
  • Strands Agents SDK v1.51.0 (6 @tool decorated functions)
  • Real agent reasoning loop with tool orchestration
  • Vercel deployment (free tier)
  • SQLite for demo persistence

What's Real vs Mocked

  • ✅ All 6 Strands tools are genuine @tool decorated functions
  • ✅ Agent initializes and runs on Vercel (verified live)
  • ✅ Diff analysis, severity classification, style checking, security scanning all produce real output
  • ✅ API endpoints: /api/health, /api/agent/status, /api/demo
  • 🔧 LLM backend: demo mode (direct tool orchestration) — production uses AWS Bedrock for full agent reasoning loop

Built With

  • ai-agents
  • code-review
  • fastapi
  • mcp
  • python
  • security
  • strands-agents-sdk
  • vercel
Share this project:

Updates

Submission history