Automated Code Reviews with AST Scope Precision
The Code Reviewer AI Agent emulates the precision of CodeRabbit. Built with the Divmora LocalHarness SDK, it analyzes pull requests across GitLab, GitHub, Bitbucket, and local workspaces—producing structured scorecards, file walkthroughs, and 1-click committable suggestions directly on changed lines.
Commit-Scoped Net Diff
Isolates author feature commits, completely filtering out merge-drift noise from master/pre-prod.
Anti-Hallucination AST
Native Go AST & multi-language scope analyzer trims context to enclosing definitions with line decoration.
1-Click Inline Suggestions
Publishes GitHub & GitLab committable replacement blocks with scoped quality badges.
Engine Architecture
graph TD
A[VCS Ingress: GitLab / GitHub / Bitbucket] --> B[Smart Diff & Commit Isolator]
B --> C[Noise Filter & Secrets Pre-Scanner]
C --> D[AST Scope Slicer: Go / Python / TS / PHP / Java]
D --> E[Divmora LocalHarness SDK]
E --> F[Review Evaluator & Comment Budgeter]
F --> G[VCS Publisher: Inline Suggestions, Scorecards, Labels]
GitLab CI/CD Integration
Automatically review GitLab Merge Requests (both GitLab.com SaaS and Self-Hosted instances) on every commit.
stages:
- test
- review
# AI Code Review runs in parallel with test, non-blocking
ai-code-review:
stage: review
image: ghcr.io/divmora/code-reviewer-ai-agent:latest
rules:
# Run on Merge Requests (excluding draft / WIP MRs)
- if: '$CI_PIPELINE_SOURCE == "merge_request_event" && $CI_MERGE_REQUEST_TITLE !~ /^(Draft|WIP):/i'
allow_failure: true
variables:
# Masked CI/CD Variables configured in Settings > CI/CD > Variables
CODE_REVIEWER_LITELLM_BASE_URL: "$LITELLM_BASE_URL"
CODE_REVIEWER_LITELLM_API_KEY: "$LITELLM_API_KEY"
CODE_REVIEWER_LITELLM_MODEL: "workers-ai/@cf/zai-org/glm-5.2"
script:
- code-reviewer \
--url "$CI_MERGE_REQUEST_PROJECT_URL/-/merge_requests/$CI_MERGE_REQUEST_IID" \
--token "$GITLAB_TOKEN" \
--skip-tls-verify \
--post \
--update-description \
--update-labels
- Allow Failure: Setting
allow_failure: trueensures the AI review provides rich insights without blocking deployments. - Self-Hosted SSL: Use
--skip-tls-verifyfor internal enterprise GitLab servers with private CA certificates. - Watermark Dedup: Automatically skips review if the target commit SHA has already been evaluated.
GitHub Actions Integration
Run automated reviews on Pull Request creation and code synchronization using GitHub Actions.
name: AI Code Review
on:
pull_request:
types: [opened, synchronize, reopened, ready_for_review]
jobs:
review:
if: github.event.pull_request.draft == false
runs-on: ubuntu-latest
permissions:
contents: read
pull-requests: write
statuses: write
steps:
- name: Run Code Reviewer Agent
uses: docker://ghcr.io/divmora/code-reviewer-ai-agent:latest
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
CODE_REVIEWER_LITELLM_BASE_URL: ${{ secrets.LITELLM_BASE_URL }}
CODE_REVIEWER_LITELLM_API_KEY: ${{ secrets.LITELLM_API_KEY }}
CODE_REVIEWER_LITELLM_MODEL: "workers-ai/@cf/zai-org/glm-5.2"
with:
args: >-
--url ${{ github.event.pull_request.html_url }}
--token ${{ secrets.GITHUB_TOKEN }}
--post
Bitbucket Pipelines Integration
Automate code review feedback on pull requests inside Bitbucket Cloud or Data Center.
pipelines:
pull-requests:
'**':
- step:
name: AI Code Review
image: ghcr.io/divmora/code-reviewer-ai-agent:latest
script:
- code-reviewer \
--url "$BITBUCKET_GIT_HTTP_ORIGIN/pull-requests/$BITBUCKET_PR_ID" \
--token "$BITBUCKET_TOKEN" \
--post
Model & LiteLLM Resolution Hierarchy
The agent resolves LiteLLM credentials, models, and endpoints following a 4-tier resolution chain:
--litellm-base-url--litellm-api-key--litellm-model--litellm-endpoint
CODE_REVIEWER_LITELLM_BASE_URLCODE_REVIEWER_LITELLM_API_KEYCODE_REVIEWER_LITELLM_MODELCODE_REVIEWER_LITELLM_ENDPOINT
LITELLM_BASE_URLLITELLM_API_KEYLITELLM_MODELLITELLM_ENDPOINT
~/.divmora/config/litellm.json- Named endpoint or default endpoint resolved automatically.
Review Sensitivity Profiles
Control review tone and strictness via the --profile flag:
Focuses strictly on critical errors and security flaws. Ignores styling and minor nits.
Thorough and practical. Catches edge cases, security, performance, and maintainability issues.
Strict audit mode. Flags subtle bugs, design anti-patterns, test gaps, and typing inconsistencies.
CLI Flags Reference
| Flag | Default | Description |
|---|---|---|
| --url | "" | PR / MR URL (GitLab, GitHub, Bitbucket) |
| --workspace | "." | Local workspace directory to review |
| --diff | false | Review uncommitted local git changes |
| --token | $TOKEN | VCS API access token |
| --post | false | Post inline comments, scorecard description, and labels |
| --skip-tls-verify | false | Skip TLS verification for internal GitLab self-hosted instances |
| --profile | "balanced" | Sensitivity profile: chill, balanced, assertive |
| --max-comments | 15 | Comment budget cap prioritizing High > Medium > Low |
| --version, -v | false | Print version metadata and exit |