Skip to main content

Features

CodePeel is an AI code review engine that analyzes every pull request for bugs, security vulnerabilities, performance issues, and architectural problems. Reviews are triggered automatically from GitHub PRs, manually from the VS Code extension, or programmatically via the MCP server. Every review produces inline comments on the exact lines that need attention, a walkthrough summary, a health score, and optional automation like auto-fix PRs.


Inline Comments on Your PR

When CodePeel reviews a pull request, it posts findings as GitHub inline comments directly on the lines that need attention. Each comment appears in the "Files changed" tab of your PR, positioned on the exact line where the issue was detected. Comments are posted incrementally as each analysis layer completes, so you start seeing results within seconds of the review starting.

Every inline comment follows a structured format designed for quick scanning and immediate action. The comment begins with a severity badge that tells you at a glance how serious the issue is, followed by a title with a relevant emoji to indicate the category. The body uses bullet-point sections to separate what the problem is, what impact it has, and what you should do about it. When CodePeel can generate a concrete code fix, the comment includes a problemCode block showing the exact buggy code and a fixCode block with the corrected version — copy-paste ready.

Severity Badges

SeverityBadgeWhen it's used
Critical🔴 CriticalSecurity vulnerabilities, data loss, crashes, race conditions
High🟠 MajorBugs causing incorrect behavior, missing error handling
Medium🟡 MinorPerformance issues, potential edge cases, code smells
Low🔵 TrivialStyle improvements, naming suggestions (dashboard only)
Info⚪ InfoInformational notes, context

Trivial (🔵) findings are stored in your CodePeel dashboard only. They are not posted as PR comments to keep noise low.


Walkthrough Summary

Every PR gets a walkthrough comment posted on the Conversation tab of your pull request. This is a collapsible section that provides a high-level overview of the entire review, giving reviewers context before they dive into individual findings.

The walkthrough includes a plain-English summary of what the PR does, a breakdown of findings by category (bugs, security, performance, best practices), a review effort score, and a health score. It also lists all files reviewed grouped by module, with a per-module finding count so you can see which areas of the codebase need the most attention.

The walkthrough is structured as follows:

  • Commits — which commit SHA is being reviewed against which base
  • Files reviewed — collapsible list of all files grouped by module
  • Changes table — module-level breakdown showing file count and finding count per module
  • Finding counts — table with counts for bugs, security, performance, and best practices
  • Review effort — a 1-5 scale (⬤◯◯◯◯ to ⬤⬤⬤⬤⬤) indicating how complex the PR is to review
  • Health score — aggregate quality score (0-100) with emoji indicator
  • Inline comments count — total number of comments posted on the PR

Sequence Diagrams

For complex PRs, CodePeel generates a mermaid sequence diagram showing the logic flow of the changes. This diagram is appended to the walkthrough and renders natively in GitHub's markdown viewer. Only valid mermaid diagram types are accepted: sequenceDiagram, flowchart, graph, classDiagram, stateDiagram, erDiagram, gantt, pie, journey, gitgraph.

Sequence diagrams are enabled by default. To disable them, set in your repository configuration:

walkthrough:
  auto_sequence_diagram: false

Health Score

A 0-100 number representing overall code quality for a single review. The health score appears in the walkthrough comment on your PR and on the PR detail page in the dashboard. It gives you an instant signal about whether a PR is safe to merge or needs more work.

The score starts at 100 and deducts points for each finding based on severity. Caps prevent a burst of minor issues from tanking your score unfairly. For example, even if a PR has 20 minor findings, the maximum deduction from minor issues is capped at 15 points.

How it's calculated

SeverityDeduction per findingMaximum penalty (cap)
Critical-20-50
High/Major-10-30
Medium/Minor-4-15
Low/Trivial-1-5

The formula is:

healthScore = max(0, 100 - penalty)
penalty = min(50, criticals × 20) + min(30, highs × 10) + min(15, mediums × 4) + min(5, lows × 1)

What the score means

ScoreEmojiRisk Level
80-100🟢Low risk — safe to merge
60-79🟡Moderate risk — review findings before merging
40-59🟠High risk — significant issues present
0-39🔴Critical risk — do not merge without addressing findings

Use Pre-merge Checks to automatically block merges when the health score drops below your threshold or when specific conditions are met.


Analysis Layers

CodePeel runs four independent analysis passes in parallel on every PR. Each layer specializes in a different class of issues, and all four run simultaneously regardless of PR size. This parallel architecture means you get comprehensive coverage without waiting for sequential passes to complete.

LayerWhat it detectsSpeedDetails
Secret scanningAPI keys, tokens, credentials, custom patternsInstant (posted first)
AI analysisBugs, security, performance, best practices~10-30sAI-powered deep analysis
SASTStatic analysis security patterns (CWE-based)~10-20sAI-based pattern matching
Architecture reviewDesign patterns, coupling, SRP violations~15-25sSkipped when securityOnly: true

Secret Scanning Layer

The secret scanning layer runs first and posts results within seconds, before any other analysis completes. It uses a two-pronged approach:

Regex-based scanning detects known secret patterns including AWS Access Keys, OpenAI/Stripe keys, GitHub tokens, Firebase API keys, JWTs, database connection strings, RSA private keys, and more. It also scans for injection vulnerabilities (SQL injection, timing attacks, PCI DSS violations), performance anti-patterns (N+1 queries, unbounded caches), and memory safety issues (unbounded list growth, caches without eviction).

Results are deduplicated across detection methods to prevent duplicate comments.

You can add custom secret patterns in the Repository Configuration modal in the web dashboard:

security:
  custom_patterns:
    - "MY_SECRET_[A-Z]{10}"
    - "INTERNAL_TOKEN_[a-f0-9]{32}"

AI Analysis Layer

The AI analysis layer is the core of CodePeel's review engine. It uses multiple AI providers for reliability, falling back if one is unavailable. The AI receives the full diff along with your configuration (custom instructions, expert rules, review profile) and produces structured findings with problem code, fix code, and explanations.

The AI is guided by strict severity criteria to avoid noise. Critical findings are reserved for security vulnerabilities, data loss, and crashes. The AI will not flag architecture opinions on files under 100 lines, generic "consider refactoring" suggestions without concrete fixes, or style preferences.

For large PRs, the diff is analyzed in sections and findings are aggregated and deduplicated across sections.

SAST Layer

The SAST (Static Application Security Testing) layer runs an AI-based pattern analysis focused specifically on CWE-classified security vulnerabilities. It operates independently from the AI analysis layer, providing a second opinion on security issues. Findings from SAST are deduplicated against AI findings using proximity matching (same file, within 3 lines).

Architecture Review Layer

The architecture review layer evaluates design patterns, modularity, complexity, and structural risks. It is automatically skipped when securityOnly: true is set in your configuration. Architecture findings use additional filtering to suppress noise:

  • Architecture opinions on small files are suppressed to avoid noise
  • Findings are capped at 4 per file to prevent comment flooding
  • Vague recommendations without concrete fixes are filtered out
  • Findings within 3 lines of an already-posted SAST finding are deduplicated

Incremental Reviews

When you push new commits to an existing PR, CodePeel reviews the changes and scans for new issues. Use the learnings system to teach CodePeel your conventions, or use @codepeel ignore: in a PR comment to suppress a pattern going forward.


Finding Categories

CodePeel classifies every finding into one of four categories. Each category maps to a specific type of code issue and is displayed with a distinct icon in the walkthrough summary.

CategoryIconExamples
Bug🐛Logic errors, null references, off-by-one, unhandled promises, race conditions
Security🔒SQL injection, XSS, path traversal, hardcoded secrets, timing attacks, PCI violations
Performance⚡N+1 queries, unnecessary re-renders, memory leaks, unbounded caches
Best Practice📐Error handling, naming, DRY violations, resource leaks, coupling issues

Each finding provides a specific recommendation: bugs and security vulnerabilities that will break in production, performance improvements and code smells, or minor style suggestions.


Quality Gates and Noise Reduction

CodePeel applies multiple layers of filtering to ensure you only see actionable, high-value findings. The goal is zero false positives and zero noise.

Slop Detection

Findings are automatically filtered if they contain vague, generic language without concrete fixes. A finding is classified as "slop" and removed if:

  • The explanation is under 20 characters
  • It contains two or more generic phrases like "consider refactoring", "could be improved", "add proper error handling"
  • The problem code is a comment, less than 10 characters, or identical to the fix code
  • The fix code contains placeholder markers like [insert, [your, or ...
  • The title says "magic number" but the number is a legitimate constant (HTTP status codes, common timeouts, port numbers)

Architecture Noise Suppression

Architecture opinions are suppressed on files under 120 lines. Patterns like "single responsibility violation", "tight coupling", "should be split", and "dependency injection" are only flagged on files with substantial complexity where the feedback is actionable.

Per-File Caps

Findings are capped at 4 per file, prioritized by severity. This prevents comment flooding on files with many minor issues. Critical and high-severity findings always take priority over medium and low.

Confidence Scoring

For borderline findings, CodePeel may re-evaluate the finding to confirm it's worth surfacing. Low-confidence findings are suppressed. This catches hallucinations and false positives that pass the initial filters.


Deduplication

When multiple analysis layers flag the same issue on the same line, you only see one comment. Findings on the same file within a few lines of each other are consolidated — the higher-severity finding wins. This prevents comment flooding while ensuring no valid issue is missed.


Custom Rules

Custom regex rules let you enforce team-specific conventions that the AI might not catch on its own. Rules are defined in your repository configuration (via the Web Dashboard) and run as a dedicated enforcement pass, separate from the AI analysis.

Custom rules require a Pro or Max plan. On the free tier, custom rules are silently skipped.

Defining rules

rules:
  - id: no-console-log
    pattern: "console\\.log\\("
    message: "Remove console.log statements before merging to production."
    severity: medium
    paths:
      - "src/**/*.ts"
    exclude_paths:
      - "src/**/*.test.ts"
    category: best-practice

  - id: no-raw-sql
    pattern: "\\$\\{.*\\}.*(?:SELECT|INSERT|UPDATE|DELETE)"
    message: "Use parameterized queries instead of string interpolation in SQL."
    severity: critical
    paths:
      - "**/*.ts"

Rule fields

FieldRequiredDescription
idNoUnique identifier for the rule (max 50 chars). Auto-generated as rule-XXXXXX if missing.
patternNoRegex pattern to match against added lines (max 200 chars). A rule without a pattern is a metadata-only rule.
messageYesMessage shown when the rule is violated (max 500 chars). Rules without a message are dropped at parse time.
severityNocritical, high, medium, or low (default: medium)
pathsNoGlob patterns for files to check (default: all files)
exclude_pathsNoGlob patterns for files to skip
categoryNoCustom category label shown in the comment

Rules are capped at 50 per repository to prevent prompt bloat.

Regex safety: Patterns in security.custom_patterns are validated for ReDoS safety. Custom rules in the rules field are not automatically validated — be careful with nested quantifiers in your patterns.

Context-aware matching

Custom rules include context-aware logic to reduce false positives. For example, if your rule flags direct database writes, CodePeel will automatically suppress the finding when the matched line is inside a transaction or batch block.


Pre-merge Checks

Pre-merge checks let you define quality gates that must pass before a PR can be merged. When a check fails, CodePeel posts a failure commit status to GitHub, which can block the merge if you have branch protection rules enabled.

Checks are configured in the dashboard and evaluated automatically after every review completes.

Available check types

Check TypeWhat it evaluatesFailure condition
bug_densityNumber of bugs foundBugs exceed your threshold
security_blockerAny security findingsOne or more security issues detected
max_issuesTotal findings (bugs + security + performance)Total exceeds your threshold
critical_findingsCritical-severity findingsOne or more critical findings detected

How it works

  1. CodePeel completes the review and calculates metrics
  2. All enabled checks for your account are evaluated against the review metrics
  3. Each check records a pass/fail event with details
  4. If any check with error severity fails, a failure commit status is posted
  5. Checks with warning severity are recorded but do not block the merge
  6. Results are saved with the review for dashboard display

The commit status appears as codepeel/premerge in GitHub's checks tab. Link it to a branch protection rule to enforce merge blocking.

See the full Pre-merge Checks documentation for setup instructions.


Web Review Explorer

In addition to receiving inline GitHub comments, you can inspect, filter, and take action on reviews directly in the CodePeel Web Dashboard.

Pull Request Overview (/app/prs)

The central PR explorer aggregates all reviewed pull requests across your connected repositories:

  • Multiple View Modes: Switch between Timeline, Grid, and Table views depending on whether you want a chronological stream or a dense tabular overview.
  • Repository & Status Filters: Filter by specific repositories or review outcome (success vs error).
  • Full Search: Quickly locate PRs by repository name, PR title, or pull request number.
  • CSV Export: Export your filtered list of pull requests and review metrics to CSV for offline reporting and audits.

PR Detail Explorer (/app/prs/[id])

Clicking any reviewed PR opens the detailed review explorer:

  • Severity & Category Filters: Filter findings by severity (🔴 Critical, 🟠 Major, 🟡 Minor, ⚪ Info) and category (Bugs, Security, Performance, Best Practices) to prioritize high-risk issues.
  • Inline Diffs & Code Snippets: View the exact lines of code flagged alongside syntax-highlighted problemCode and fixCode snippets.
  • One-Click "Commit Fix": When CodePeel suggests a concrete code fix, click Commit Fix directly in the browser. CodePeel creates a dedicated fix branch and opens a pull request with the patch applied, giving you an immediate View Fix PR link to review on GitHub.
  • Auto-Generated PR Description: CodePeel summarizes the scope and intent of the PR into a copyable markdown description, ready to paste into GitHub.
  • Architecture & Sequence Diagrams: View natively rendered Mermaid diagrams visualizing the architecture and execution flow modified by the PR.
  • Pre-Merge Gate Evaluation: Inspect which pre-merge quality gates passed or failed, including specific metric thresholds.

Team Insights & Data Metrics

CodePeel provides high-level analytics to help teams track code quality trends, identify recurring hotspots, and maintain merge standards across engineering teams.

Team Insights (/app/insights)

The Insights dashboard gives engineering leads and teams visibility into code health:

  • Weekly Narrative Briefing: Automated summary comparing your engineering velocity and findings against the prior 7-day period (e.g. issues per PR trends, security issue ratios, and clean PR milestones).
  • Merge Confidence Ratings: Transparent, rules-based rating per PR derived directly from finding severity:
    • Safe to merge (🟢) — 0 findings detected across all categories (clean PR).
    • Looks good (🟢) — 0 critical, 0 major, and 3 or fewer minor findings.
    • Needs review (🟡) — 1–2 major findings, or more than 3 minor findings.
    • Risky (🔴) — 1 or more critical vulnerabilities, or more than 2 major issues.
  • Progress & Habits to Break:
    • Your Progress: Tracks whether issue frequency per PR across categories (security, bugs, performance, architecture) is improving compared to older PRs.
    • Habits to Break: Highlights recurring issue patterns that have appeared across 2 or more pull requests so you can address root causes.
    • Before Your Next PR: Actionable checklist and tips generated from active weak spots and recent findings.
  • Summary Metrics: High-level counters for total PRs reviewed, total findings caught, average findings per PR, and clean PR count.

Data Metrics & Review Logs (/app/data-metrics)

The Data Metrics page provides complete operational logs and audit capability:

  • Review Audit Logs: Paginated history of every review execution, including timestamp, commit SHA, additions/deletions, author, and categorized issue counts.
  • CSV Data Export: Export complete review metrics across custom date ranges. Perfect for compliance verification, SOC2 audits, and engineering KPI reporting.