AI Code Review for Open-Source Maintainers
A first-pass LLM review on community PRs, following one written rubric and running on your own model key.
Last updated
What problems do Open-Source Maintainers face in code review?
- Hundreds of community PRs per month — too many for maintainers to review thoroughly
- Contributors don't know the project's unwritten conventions, leading to style and architecture mismatches
- Security-sensitive PRs (dependency updates, auth changes) need expert review but maintainers are volunteers
- Review load is a common source of maintainer burnout
How does Argus fit your workflow?
- Argus can post a first-pass review on community PRs before a maintainer looks. With auto-review on, opened PRs are reviewed automatically on your key, fork PRs included; with it off, a maintainer ticks the trigger checkbox or comments @argus-eye review (the handle is your GitHub App's slug; argus-eye is the default)
- Conventions read from reviewed diffs and patterns maintainers teach with @argus-eye remember go into later review prompts. Style and formatting are never findings under the Review Laws, so keep those in your linter
- Files on auth, token, session, credential, and similar paths get a security-focused pass, and a Semgrep pre-pass runs on the changed files. Argus does not check dependency updates against vulnerability databases
- Each inline comment states the problem and why it matters, adds a suggested fix when the model has one, and cites a stored pattern or rule when one closely matches
Which Argus features matter most for your team?
- Capped, ranked output
- One GitHub review per run with at most 10 inline comments, blocking findings first, and a one-line verdict such as 'Fix 2 blocking findings before you merge.' The rest are counted and linked to the dashboard
- Convention learning
- Conventions are extracted from reviewed diffs and fed into later reviews, and when a new one contradicts a stored one, Argus asks on the PR which one stands. It does not replace a linter config
- Review memory
- When a maintainer replies to an Argus comment explaining why it is wrong, the explanation can be stored as a repo pattern and similar findings are dropped or downgraded later. Replies from people without write access get an answer but change nothing
- BYOK (Bring Your Own Key)
- Reviews run on your own LLM provider key: the dashboard lists 11 providers, all called through one OpenAI-compatible adapter. Argus has no seats and no paid tier; you pay your provider for tokens
Only people with write access can launch a review with @argus-eye review or the trigger checkbox; with auto-review on, opened PRs, fork PRs included, are reviewed on the maintainer's key