A review you can argue with
Most tools summarize a diff. inline reads the code around it, forms a position, then throws out anything it cannot support from what it read. What is left goes on the pull request, one comment per defect, on the line that causes it.
Two tiers, so
cost tracks risk
Haiku triages every pull request into substantive, trivial, or skipped. Only substantive work reaches Opus and its agentic read, grep and trace loop. A dependency bump costs a fraction of a cent; a rewrite of the payment path gets the full pass.
Every pull request the agent has processed, newest first.
| Pull request | Verdict | Findings | Cost | When |
|---|---|---|---|---|
acme/payments-api#4127 Add idempotency keys to the charge endpoint by priya · nextjs · Opus 5 | substantiveHigh risk | 4 | $0.312 | 2m ago |
acme/payments-api#4126 Bump stripe SDK to the current major by dependabot · nextjs · Haiku 4.5 | trivial | 0 | $0.002 | 9m ago |
acme/ledger#881 Session state machine + per-tenant rate limiter by tomas · dotnet · Opus 5 | substantiveMed risk | 2 | $0.134 | 24m ago |
acme/mobile#2310 Retry image uploads on transient 5xx by jules · expo · Opus 5 | substantive | 1 | $0.098 | 1h ago |
acme/ledger#879 Document-access audit log by priya · dotnet · Opus 5 | substantive | 6 | $0.661 | 3h ago |
acme/web#5502 Fix dimmed rows that never reset after filtering by karri · nextjs · Opus 5 | substantive | 2 | $0.147 | 4h ago |
acme/web#5501 Update the onboarding copy by sam · nextjs · Haiku 4.5 | skipped | 0 | $0.001 | 5h ago |
acme/etl#640 Backfill tenant ids on historical charge rows by tomas · python · Opus 5 | substantiveHigh risk | 3 | $0.221 | 6h ago |
acme/mobile#2309 Cache the session token across cold starts by jules · expo · Opus 5 | substantive | 1 | $0.076 | 8h ago |
Every finding
carries its evidence
Severity, category, file and line, and a confidence score. Cost is broken down per model and per role, so you can see exactly what the review spent and where. Suppressed findings keep their reason instead of disappearing.
$0.312
88,402
61,180
9,744
1m 47s
This PR adds idempotency keys to the charge endpoint and a replay cache in front of it. The data model is right, but the key is persisted after the charge rather than before it, so concurrent retries can double charge; the replay cache is also keyed without the tenant id, which lets one tenant read another tenant's cached response.
Idempotency key is written after the charge, not before
Replay cache key omits the tenant id (IDOR)
Retry budget is never reset between attempts
And it checks
its own work
Where a claim is testable, the sandbox tests it before the comment is posted. A finding that the run contradicts never reaches your team.
- Install dependenciesnpm ci
- Type checknpx tsc --noEmit
- Existing suitenpx vitest run
- Authored testsnpx vitest run charges.spec.ts
- Browser flownpx playwright test checkout
Included
Put it on one repository
Connect GitHub, enable a repo, and the next pull request opened gets a review.