Autonomous Review for GitHub Understanding & Security

A hundred eyeson every commit.

ARGUS reads a repository the way a senior engineer would. Six specialised agents run in parallel to produce security findings, review comments, and documentation grounded in the code that is actually there.

Agents
06 parallel
Surfaces
Review · Docs · Graph
Input
Repo URL / ZIP
01The read

Most review tools

skim. ARGUS reads.

A diff on its own is not enough context to judge a change. ARGUS parses the whole snapshot first — every function, class and import — then indexes it so each agent can retrieve the code that matters to its question rather than reading the same oversized blob.

That context is what separates a real finding from a guess. Every item in the report cites a file and a line, carries a confidence score, and names the agent that raised it. Anything below the confidence floor is discarded rather than shipped as filler.

api/sessions.py · reviewed
41async def create_session(user_id: str, raw: str):
42 query = f"SELECT * FROM users WHERE id = '{user_id}'"
43 query = "SELECT * FROM users WHERE id = %s"
44 row = await db.fetch(query, user_id)
45 token = hashlib.md5(raw.encode()).hexdigest()
46 token = secrets.token_urlsafe(32)
47 return Session(user=row, token=token)
2 replaced1 critical1 high6 agents
02Findings

Evidence, not opinion.

criticalapi/sessions.py:42

Interpolated identifier reaches the query builder

The user identifier is formatted directly into SQL. Any caller controlling that value controls the statement. Parameterise the query and let the driver bind the value.

highapi/sessions.py:45

Session token derived from an unsuitable digest

MD5 is fast and collision-prone, which is the opposite of what a session token needs. Generate tokens from a CSPRNG instead of hashing user input.

cleanapi/deps.py

No findings above the confidence floor

Six agents reported nothing actionable here. ARGUS suppresses low-confidence noise rather than padding the report — an empty section is a real result.

03The roster

Six specialists, one pass.

01SecurityHardcoded credentials, injection paths, unsafe execution, weak crypto and auth handling.Injection · Secrets
02Bug & SafetySwallowed exceptions, unhandled null paths, dynamic evaluation and silent failure modes.Correctness
03PerformanceRepeated I/O inside loops, avoidable full scans, and nested iteration over large inputs.Hot paths
04ArchitectureGod files, tangled layering, and business logic leaking into transport or UI code.Boundaries
05ReadabilityUndocumented non-trivial functions, misleading names, and control flow that blocks review.Maintainability
06AccessibilityMissing alternative text, non-semantic interactive elements, and keyboard traps in markup.Interface
04Pipeline

Four moves,

no waiting.

The expensive part of review is not thinking — it is queueing. ARGUS decides what deserves a model call before making one.

01

Point at a repository

A GitHub URL or a ZIP upload. ARGUS pulls a snapshot, parses every supported source file, and indexes it for retrieval. Nothing is installed and no OAuth dance is required.

02

Route before spending

The change is classified first. A documentation-only edit skips the language models entirely; a small diff takes a single compact pass. Work is only sent to an agent that can act on it.

03

Run agents in parallel

Selected agents execute concurrently rather than in sequence, alongside structure analysis and file summarisation. One slow agent no longer holds the others hostage.

04

Read the report

Findings are deduplicated, ranked by severity and confidence, then written in the register of the persona you chose — from a first-week intern to a production backend engineer.

05Output

Four surfaces, one run.

Surface 01

Review

Ranked findings grouped by file, each with evidence, a severity, a confidence score, and the agent that raised it.

Surface 02

Code Explainer

A plain-English health score, per-file summaries, and expandable walkthroughs for anyone who does not already know the codebase.

Surface 03

Documentation

README, per-module documentation, docstrings, and an onboarding guide generated from the parsed source rather than guessed.

Surface 04

Dependency graph

A force-directed map of how modules actually import one another. Drag nodes, isolate a layer, and trace a file's neighbourhood.

Point it at a repository and read the report.

ARGUS