A code review on every pull request.
Install the GitHub App and every PR gets a concrete, friendly review within minutes: what the PR does, what is actually broken, what you might consider. No noise, no flattery — and free for open source. The diff automatically goes to the cheapest model that can handle it, and every review is traceable down to the cent.
From webhook to review, with a guardrail up front
GitHub knocks, ReviewPilot verifies the signature first and only then does anything happen. The diff determines which model does the work; the answer comes back as one comment. Underneath runs the same correlation thread as through the rest of the lab: every review is a cost line.
Seven steps, one comment
From PR to review
- GitHub sends a webhook the moment a pull request opens or updates
- The signature (HMAC-SHA256) is verified — no valid secret, no review
- Public repo → free tier; private repo → customer check
- A GitHub App token fetches the diff, read-only and per installation
- Diff size determines the model: small → DeepSeek V4 Flash, large → DeepSeek V4 Pro
- The review comes back as one clean PR comment, referencing file and line
- Every call gets a correlation id, so AgentLedger records the cost per review
Concrete, specific, and short where it can be
Every review follows the same shape: summary, what is really broken, what you should consider, and a few minor points. It never invents line numbers; if the diff is trivial, it says so in two lines instead of forcing feedback.
Summary. Adds a fixed-window rate limiter to the login route. Sensible approach; two edge cases need attention before merge.
Must fix.
- auth.js:38 — the counter is keyed on username only, so an attacker rotating usernames bypasses the limit. Key on IP + username.
- auth.js:51 — the window resets with Date.now() per request instead of per window, so the limit never actually triggers.
Should consider. Return 429 with a Retry-After header; add a test for the 11th attempt.
— 🧾 Review by ReviewPilot · free for open source · review.neuralex.nl
Example to illustrate the format; the content differs per PR.
Free for open source. Affordable for the rest.
Open Source
- Public repositories
- 10 reviews per repo per day
- Smart model routing
- Community support
Indie Dev
- Unlimited reviews
- Private repos included
- Priority on the stronger route
- Slack/Discord notifications
Not another bot
Right after it opens
Feedback within ~2 minutes of a PR — no queue, no manual work.
Smart routing
Small diffs to a fast, cheap model; large diffs to a stronger model. Always the cheapest one that fits.
Privacy first
No data retention, no training on your code. The review is ephemeral: used and gone.
Free for open source
Public repos get reviews at no cost. Every review is marketing at the same time.
Transparent costs
On average under € 0,05 per review, with full cost logging via AgentLedger.
No vendor lock-in
Runs on our own model router. No dependency on a single American API.
Where it stands now
ReviewPilot runs in dogfood: the chain is built and tested, and reviews our own repos. The amounts and times above are prices and design targets — not production measurements. As soon as the test week is done, we replace them with real numbers from the register, just like with AgentLedger.
Want AI reviews on your repos?
ReviewPilot installs as a GitHub App and posts back a substantiated review from the very first PR. Free for open source; for private repos we run a demo on your own code.