CodeReview Sentinel — Autonomous PR Triage Agent
Code review is one of the most important yet time-consuming tasks in software development. Every PR needs careful review for complexity, risk, style, security — and review backlogs are a universal bottleneck that slows teams down.
CodeReview Sentinel solves this by running an autonomous AI agent that triages PRs the moment they're opened. Built with the Strands Agents SDK, the agent uses 6 callable tools in an autonomous reasoning loop:
- PERCEIVE —
analyze_diffextracts complexity metrics (lines added/removed, files changed, complexity score) - ANALYZE —
classify_severityassesses risk level based on file patterns and dangerous code detection - CHECK —
check_stylevalidates code style compliance for Python, JavaScript, TypeScript, and Go - SCAN —
security_scandetects 15+ vulnerability patterns (hardcoded secrets, RCE, XSS, SQLi, pickle deserialization, SSL bypass) - REPORT —
generate_review_commentproduces a structured markdown review comment ready to post - SUMMARIZE —
draft_pr_summarygenerates a concise PR summary for maintainers
The agent autonomously decides which tools to call, in what order, and synthesizes results into a coherent, actionable review. It surfaces only what matters — risk factors, security findings, style issues — and gives a clear recommendation: auto-approve, needs review, or block merge.
Why this is a Professional Agent
Code review is a repetitive, judgment-heavy task that every developer does. CodeReview Sentinel makes developers dramatically better at it by handling the first-pass triage automatically, letting human reviewers focus on the nuanced decisions that require human judgment.
Tech Stack
- Python + FastAPI backend
- Strands Agents SDK v1.51.0 (6 @tool decorated functions)
- Real agent reasoning loop with tool orchestration
- Vercel deployment (free tier)
- SQLite for demo persistence
What's Real vs Mocked
- ✅ All 6 Strands tools are genuine @tool decorated functions
- ✅ Agent initializes and runs on Vercel (verified live)
- ✅ Diff analysis, severity classification, style checking, security scanning all produce real output
- ✅ API endpoints: /api/health, /api/agent/status, /api/demo
- 🔧 LLM backend: demo mode (direct tool orchestration) — production uses AWS Bedrock for full agent reasoning loop
Built With
- ai-agents
- code-review
- fastapi
- mcp
- python
- security
- strands-agents-sdk
- vercel
Log in or sign up for Devpost to join the conversation.