4 min read

PR-Agent: Open-Source AI Code Review for Pull Requests (GitHub, Scanned)

An open-source AI reviewer that describes, reviews and suggests fixes on your pull requests.

PR-Agent logo
✅
Scan: safe. Nothing malicious. One thing to know: PR-Agent reads comments from anyone who can comment on your repository, and its /help_docs tool was switched off after a report that an untrusted commenter could use it to leak the workflow's GITHUB_TOKEN. Scanned Oct 3, 2026; the full report is below.

PR-Agent reviews pull requests. Once it is set up on a repository it answers commands left as PR comments: /describe writes a title, summary and walkthrough, /review flags likely bugs, security issues and missing tests, /improve proposes concrete code suggestions, and /ask answers free-form questions about the change. Each command is a single model call that the project puts at about 30 seconds, and a compression strategy lets it handle large diffs.

It runs wherever your code lives: as a GitHub Action, a webhook server, a Docker container or a CLI, against GitHub, GitLab, Bitbucket, Azure DevOps and Gitea. Models are reached through LiteLLM, so OpenAI, Claude, Gemini, DeepSeek, Bedrock, Ollama and others all work, and review behavior is set in a TOML configuration file.

PR-Agent was created by Qodo, formerly CodiumAI, which has since donated it to the community; it now lives in its own GitHub organization, is MIT licensed and has about 13,000 stars. It is separate from Qodo's commercial review product.

Who it is for

Development teams that want an automatic first-pass review on every pull request without sending code to a third-party review service, and open-source maintainers who would like PR summaries written for them.

Getting started

1. Install the CLI

pip install pr-agent

2. Set a model key and review any pull request from your terminal

export OPENAI_KEY=your_key_here && pr-agent --pr_url https://github.com/owner/repo/pull/123 review

3. Once the GitHub Action is installed, comment on a PR to run a tool

/describe   /review   /improve   /ask "What does this PR change?"

For automatic reviews, the README recommends a GitHub Action: a workflow at .github/workflows/pr-agent.yml, triggered on pull requests, that runs the-pr-agent/pr-agent@main with OPENAI_KEY and GITHUB_TOKEN from repository secrets. @main tracks the latest code, so pin a release tag if you want reviews to be reproducible. Docker images moved to pragent/pr-agent from release 0.34.2.

Safety scan

We cloned The-PR-Agent/pr-agent at commit 090a7e4 on Oct 3, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.

  • No suspicious patterns, bare-IP URLs or committed binaries across 636 files and about 180,000 lines of Python. The two secret hits are placeholders: a PEM block in the GitHub installation docs and <GITHUB PRIVATE KEY> in pr_agent/settings/.secrets_template.toml.
  • setup.py has a custom command class. We read it: it copies the docs folder's Markdown into the package as help resources at build time, and does nothing else.
  • Issue #2445 reported that /help_docs let untrusted commenters change the git clone target and send the GITHUB_TOKEN to their own host. The issue was closed in June 2026 and the README says the tool stays disabled since 0.36.1 pending a full fix. On a public repository, consider limiting which events trigger the action.
  • uv.lock pins 186 Python packages with no known advisories. The five advisories (3 high, 2 moderate) are all in docs/package-lock.json, the documentation site's build tooling (serialize-javascript, braces, http-cache-semantics, uuid), which never ships with the tool.
  • Nine workflows. The pull_request_target one is release-drafter.yml, which labels and drafts release notes without checking out PR code. All 20 third-party actions are pinned to commits. Security policy, Dependabot, CodeQL, licence, contributing guide and code of conduct present.

What the scanner counted

CheckResult
Secrets2 candidates found and read; see the notes above.
Suspicious codeNone found.
Install-time code1 setup.py with custom install logic
Committed binariesNone.
CI workflows9 workflows. 1 uses pull_request_target, none check out the pull request head. 0 of 20 third-party actions pinned to a tag rather than a commit.
Network hosts40 distinct hosts referenced from source; most often github.com, example.test, api.github.com, app.asana.com. No URLs to bare IP addresses.
Known vulnerabilities5 advisories across 1,384 pinned packages: 0 critical, 3 high, 2 moderate, 0 low. docs/package-lock.json: 1,319 packages, 5 advisories; uv.lock: 186 packages, 0 advisories.
Project hygieneHas security policy, automated dependency updates, CodeQL, licence file, contributing guide.
OpenSSF ScorecardNot scored: the project is not in Scorecard's weekly index.

The raw findings

Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.

Secret candidates (2, redacted)
WhereRuleMatch
docs/docs/installation/github.md:810private-key-----B…--- (31 chars)
pr_agent/settings/.secrets_template.toml:74private-key-----B…--- (31 chars)
Worst known vulnerabilities (5 of 5)
AdvisorySeverityPackageSummary
GHSA-vfj7-8cjw-p6xmhighbraces@3.0.3braces vulnerable to stack-exhaustion denial of service through deeply nested patterns
GHSA-ch52-4w7c-c8xphighhttp-cache-semantics@4.2.0http-cache-semantics max-stale handling can disclose cross-user cached responses
GHSA-5c6j-r48x-rmvqhighserialize-javascript@6.0.2Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()
GHSA-qj8w-gfj5-8c6vmoderateserialize-javascript@6.0.2Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects
GHSA-w5hq-g745-h8pqmoderateuuid@8.3.2uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided
Workflows worth a look

By the numbers

Stars13.2K
Forks1,922
Contributors390
Commits5,777
Open issues22
Open pull requests20
Releases39
Latest releasev0.47.0
LicenceMIT
Main languagePython
Project age3 years
Last pushOct 3, 2026
Tracked files636
Lines of code180.2K
Checkout size12 MB

Lines by language: Python 164.2K, Markdown 8,658, TOML 3,745, CSS 1,433, YAML 1,181, JavaScript 652.

Questions

Is PR-Agent free?

Yes. PR-Agent is MIT licensed and free to self-host. You pay for the model calls it makes on your own key, one call per command. Qodo, its original creator, sells a separate and broader review platform with a free tier for open-source projects; PR-Agent is not that product.

Does PR-Agent send my code anywhere?

Only to the model provider you configure. Self-hosted, the diff goes from your runner or server to that provider's API and nowhere else, so the privacy terms that matter are your model provider's. A local model through Ollama keeps it in-house entirely.

Which Git platforms does PR-Agent support?

GitHub, GitLab, Bitbucket, Azure DevOps and Gitea. GitHub can use the Action or a webhook app; the others are set up through webhooks or the CLI, with a guide for each in the docs at docs.pr-agent.ai.


This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.