Interpolated identifier reaches the query builder
The user identifier is formatted directly into SQL. Any caller controlling that value controls the statement. Parameterise the query and let the driver bind the value.
ARGUS reads a repository the way a senior engineer would. Six specialised agents run in parallel to produce security findings, review comments, and documentation grounded in the code that is actually there.
A diff on its own is not enough context to judge a change. ARGUS parses the whole snapshot first — every function, class and import — then indexes it so each agent can retrieve the code that matters to its question rather than reading the same oversized blob.
That context is what separates a real finding from a guess. Every item in the report cites a file and a line, carries a confidence score, and names the agent that raised it. Anything below the confidence floor is discarded rather than shipped as filler.
The user identifier is formatted directly into SQL. Any caller controlling that value controls the statement. Parameterise the query and let the driver bind the value.
MD5 is fast and collision-prone, which is the opposite of what a session token needs. Generate tokens from a CSPRNG instead of hashing user input.
Six agents reported nothing actionable here. ARGUS suppresses low-confidence noise rather than padding the report — an empty section is a real result.
The expensive part of review is not thinking — it is queueing. ARGUS decides what deserves a model call before making one.
A GitHub URL or a ZIP upload. ARGUS pulls a snapshot, parses every supported source file, and indexes it for retrieval. Nothing is installed and no OAuth dance is required.
The change is classified first. A documentation-only edit skips the language models entirely; a small diff takes a single compact pass. Work is only sent to an agent that can act on it.
Selected agents execute concurrently rather than in sequence, alongside structure analysis and file summarisation. One slow agent no longer holds the others hostage.
Findings are deduplicated, ranked by severity and confidence, then written in the register of the persona you chose — from a first-week intern to a production backend engineer.
Ranked findings grouped by file, each with evidence, a severity, a confidence score, and the agent that raised it.
A plain-English health score, per-file summaries, and expandable walkthroughs for anyone who does not already know the codebase.
README, per-module documentation, docstrings, and an onboarding guide generated from the parsed source rather than guessed.
A force-directed map of how modules actually import one another. Drag nodes, isolate a layer, and trace a file's neighbourhood.
ARGUS