PR-Agent reviews pull requests. Once it is set up on a repository it answers commands left as PR comments: /describe writes a title, summary and walkthrough, /review flags likely bugs, security issues and missing tests, /improve proposes concrete code suggestions, and /ask answers free-form questions about the change. Each command is a single model call that the project puts at about 30 seconds, and a compression strategy lets it handle large diffs.
It runs wherever your code lives: as a GitHub Action, a webhook server, a Docker container or a CLI, against GitHub, GitLab, Bitbucket, Azure DevOps and Gitea. Models are reached through LiteLLM, so OpenAI, Claude, Gemini, DeepSeek, Bedrock, Ollama and others all work, and review behavior is set in a TOML configuration file.
PR-Agent was created by Qodo, formerly CodiumAI, which has since donated it to the community; it now lives in its own GitHub organization, is MIT licensed and has about 13,000 stars. It is separate from Qodo's commercial review product.
- Repository: github.com/The-PR-Agent/pr-agent
- Licence: MIT (MIT License)
- Language: Python. Stars: 13.2K. Forks: 1,922. Last push: Oct 3, 2026.
- Scan: safe, Oct 3, 2026, commit 090a7e4
Who it is for
Development teams that want an automatic first-pass review on every pull request without sending code to a third-party review service, and open-source maintainers who would like PR summaries written for them.
Getting started
1. Install the CLI
pip install pr-agent2. Set a model key and review any pull request from your terminal
export OPENAI_KEY=your_key_here && pr-agent --pr_url https://github.com/owner/repo/pull/123 review3. Once the GitHub Action is installed, comment on a PR to run a tool
/describe /review /improve /ask "What does this PR change?"For automatic reviews, the README recommends a GitHub Action: a workflow at .github/workflows/pr-agent.yml, triggered on pull requests, that runs the-pr-agent/pr-agent@main with OPENAI_KEY and GITHUB_TOKEN from repository secrets. @main tracks the latest code, so pin a release tag if you want reviews to be reproducible. Docker images moved to pragent/pr-agent from release 0.34.2.
Safety scan
We cloned The-PR-Agent/pr-agent at commit 090a7e4 on Oct 3, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.
- No suspicious patterns, bare-IP URLs or committed binaries across 636 files and about 180,000 lines of Python. The two secret hits are placeholders: a PEM block in the GitHub installation docs and <GITHUB PRIVATE KEY> in pr_agent/settings/.secrets_template.toml.
- setup.py has a custom command class. We read it: it copies the docs folder's Markdown into the package as help resources at build time, and does nothing else.
- Issue #2445 reported that /help_docs let untrusted commenters change the git clone target and send the GITHUB_TOKEN to their own host. The issue was closed in June 2026 and the README says the tool stays disabled since 0.36.1 pending a full fix. On a public repository, consider limiting which events trigger the action.
- uv.lock pins 186 Python packages with no known advisories. The five advisories (3 high, 2 moderate) are all in docs/package-lock.json, the documentation site's build tooling (serialize-javascript, braces, http-cache-semantics, uuid), which never ships with the tool.
- Nine workflows. The pull_request_target one is release-drafter.yml, which labels and drafts release notes without checking out PR code. All 20 third-party actions are pinned to commits. Security policy, Dependabot, CodeQL, licence, contributing guide and code of conduct present.
What the scanner counted
| Check | Result |
|---|---|
| Secrets | 2 candidates found and read; see the notes above. |
| Suspicious code | None found. |
| Install-time code | 1 setup.py with custom install logic |
| Committed binaries | None. |
| CI workflows | 9 workflows. 1 uses pull_request_target, none check out the pull request head. 0 of 20 third-party actions pinned to a tag rather than a commit. |
| Network hosts | 40 distinct hosts referenced from source; most often github.com, example.test, api.github.com, app.asana.com. No URLs to bare IP addresses. |
| Known vulnerabilities | 5 advisories across 1,384 pinned packages: 0 critical, 3 high, 2 moderate, 0 low. docs/package-lock.json: 1,319 packages, 5 advisories; uv.lock: 186 packages, 0 advisories. |
| Project hygiene | Has security policy, automated dependency updates, CodeQL, licence file, contributing guide. |
| OpenSSF Scorecard | Not scored: the project is not in Scorecard's weekly index. |
The raw findings
Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.
Secret candidates (2, redacted)
| Where | Rule | Match |
|---|---|---|
| docs/docs/installation/github.md:810 | private-key | -----B…--- (31 chars) |
| pr_agent/settings/.secrets_template.toml:74 | private-key | -----B…--- (31 chars) |
Worst known vulnerabilities (5 of 5)
| Advisory | Severity | Package | Summary |
|---|---|---|---|
| GHSA-vfj7-8cjw-p6xm | high | braces@3.0.3 | braces vulnerable to stack-exhaustion denial of service through deeply nested patterns |
| GHSA-ch52-4w7c-c8xp | high | http-cache-semantics@4.2.0 | http-cache-semantics max-stale handling can disclose cross-user cached responses |
| GHSA-5c6j-r48x-rmvq | high | serialize-javascript@6.0.2 | Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString() |
| GHSA-qj8w-gfj5-8c6v | moderate | serialize-javascript@6.0.2 | Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects |
| GHSA-w5hq-g745-h8pq | moderate | uuid@8.3.2 | uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided |
Workflows worth a look
- .github/workflows/release-drafter.yml: pull_request_target
By the numbers
| Stars | 13.2K |
|---|---|
| Forks | 1,922 |
| Contributors | 390 |
| Commits | 5,777 |
| Open issues | 22 |
| Open pull requests | 20 |
| Releases | 39 |
| Latest release | v0.47.0 |
| Licence | MIT |
| Main language | Python |
| Project age | 3 years |
| Last push | Oct 3, 2026 |
| Tracked files | 636 |
| Lines of code | 180.2K |
| Checkout size | 12 MB |
Lines by language: Python 164.2K, Markdown 8,658, TOML 3,745, CSS 1,433, YAML 1,181, JavaScript 652.
Questions
Is PR-Agent free?
Yes. PR-Agent is MIT licensed and free to self-host. You pay for the model calls it makes on your own key, one call per command. Qodo, its original creator, sells a separate and broader review platform with a free tier for open-source projects; PR-Agent is not that product.
Does PR-Agent send my code anywhere?
Only to the model provider you configure. Self-hosted, the diff goes from your runner or server to that provider's API and nowhere else, so the privacy terms that matter are your model provider's. A local model through Ollama keeps it in-house entirely.
Which Git platforms does PR-Agent support?
GitHub, GitLab, Bitbucket, Azure DevOps and Gitea. GitHub can use the Action or a webhook app; the others are set up through webhooks or the CLI, with a guide for each in the docs at docs.pr-agent.ai.
This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.
