
Security News
Open VSX Unblocks Extension IDs Used in Malware Campaign
Open VSX has removed three extension IDs from its malicious-extension list as the legitimate publishers they impersonated move to claim the names for themselves.
@cynicalsally/cli
Advanced tools
Brutally honest code reviews. Because 'You're absolutely right' is probably absolutely wrong.
Brutally honest code reviews. Terminal + IDE.
Because "You're absolutely right" is probably absolutely wrong.
Your AI pair programmer is lying to you. Sally isn't.
She's the senior engineer your code hoped it'd never meet. Scores from 0 to 10, real issues backed by evidence, and fixes you can actually use.
Works as a CLI tool and as an MCP server in Claude Code, Cursor, and Windsurf.
npm install -g @cynicalsally/cli
Or run without installing:
npx @cynicalsally/cli roast ./src/
Requirements: Node.js 18+
.env, SSH keys, certs, and common credential files are skipped, but you should still avoid scanning secrets on purpose..sally/ in your project or ~/.sally/ on your machine..sally/ to your .gitignore and do not commit review artifacts..sally/
# Sally auto-detects what to review
sally roast
# → staged changes? reviews those
# → unstaged changes? reviews those
# → recent commit? reviews that
# → nothing? scans the directory
# Roast a file or directory
sally roast src/utils/auth.ts
sally roast ./src/
# Roast staged changes before you commit
sally roast --staged
# Compare your branch against main
sally roast --diff main
# Deep analysis with issues + actionable fixes
sally roast ./src/ -m full_truth
# Run deep analysis in the background (OS notification when done)
sally roast ./src/ -m full_truth --bg
sally roast [paths...] [options]
--staged Review only staged git changes
--diff <branch> Compare against another branch (e.g., main)
-m, --mode <mode> "quick" (default) or "full_truth" (deep dive)
--tone <tone> "cynical" (default), "neutral", or "professional"
--lang <lang> Response language code (default: "en")
--json Output raw JSON (for piping or scripting)
--fail-under <score> Exit code 1 if quality score is below threshold
--ci CI mode: compact output, exit codes
--bg Run Full Truth in background, get OS notification when done
6 CLI tools. Unlimited usage. The most honest code reviewer you'll ever work with, right in your terminal.
Sally reads the spaghetti someone left in your codebase and translates it into plain English. Just the cold, clear truth of what it actually does.
sally explain src/utils/auth.ts
# Pipe code directly
cat legacy-module.js | sally explain
# Explain the current directory
sally explain
Before and after, side by side. Sally explains why one of them is going to haunt your 3am on-call rotation.
sally refactor src/components/Dashboard.tsx
# Refactor current directory
sally refactor
Sally reviews your PR like a senior engineer who has time, opinions, and absolutely no reason to be polite.
# Review PR #42 (requires GitHub CLI)
sally review-pr 42
# Review current branch vs main
sally review-pr
# Pipe a diff
git diff main | sally review-pr
Pitch your architecture idea and Sally tells you the three ways it falls apart at scale. Cheaper than a post-mortem.
sally brainstorm "Microservices for a 2-person team?"
# Brainstorm about the current project
sally brainstorm
Sally tells you why your component re-renders on every keystroke and why your z-index is load-bearing.
sally frontend src/components/Header.tsx
# Review all frontend code in a directory
sally frontend ./src/
Run your copy by Sally before your customers do. They won't be this constructive about it.
sally marketing "Ship faster with AI-powered code reviews"
# Review your README and landing page copy
sally marketing README.md
Every tool accepts file paths, raw text, or piped stdin. Each includes 1 free trial, no account needed.
Gate your pipeline on code quality:
# GitHub Actions
- name: Sally Code Review
run: npx @cynicalsally/cli roast ./src/ --fail-under=5 --ci
--ci gives compact output with exit codes. --fail-under fails the build when the score drops below your threshold. Add --json for machine-readable output.
Sally works as an MCP server inside Claude Code, Cursor, and Windsurf.
claude mcp add cynical-sally -- npx @cynicalsally/cli mcp
Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (per project):
{
"mcpServers": {
"cynical-sally": {
"command": "npx",
"args": ["@cynicalsally/cli", "mcp"]
}
}
}
Add to ~/.codeium/windsurf/mcp_config.json:
{
"mcpServers": {
"cynical-sally": {
"command": "npx",
"args": ["@cynicalsally/cli", "mcp"]
}
}
}
| MCP Tool | What it does |
|---|---|
sally_roast | Code review with score, issues, and fixes |
sally_explain | Explain code with Sally's personality |
sally_review_pr | Review PR diffs |
sally_refactor | Refactoring suggestions with before/after |
sally_brainstorm | Feedback on ideas and approaches |
sally_frontend | Frontend/UI code review |
sally_marketing | Marketing copy review |
sally_usage | Check quota and account status |
Run sally mcp in your terminal to see setup instructions.
| Command | Description |
|---|---|
sally roast [paths...] | Review files, directories, or git changes |
sally explain [file] | Explain what code actually does |
sally refactor [file] | Refactoring with before/after code |
sally review-pr [pr] | Review a PR diff |
sally brainstorm "idea" | Feedback on ideas and approaches |
sally frontend [file] | Frontend/UI code review |
sally marketing "copy" | Marketing copy review |
sally login <email> | Log in via magic link |
sally logout | Clear stored session |
sally usage | Check your quota and account status |
sally upgrade | Upgrade to Sally's Full Suite |
sally results | View background review results |
sally mcp | MCP server setup instructions |
90 free roasts per month, no account needed. Every premium tool includes a free trial.
sally usage # Check your quota
sally upgrade # Unlock the Full Suite
~/.sally/config.jsonFor full details: cynicalsally.com/privacy
Found a bug or have a feature idea? Open an issue. Sally promises to only judge your issue title a little.
FAQs
Brutally honest code reviews. Because 'You're absolutely right' is probably absolutely wrong.
The npm package @cynicalsally/cli receives a total of 57 weekly downloads. As such, @cynicalsally/cli popularity was classified as not popular.
We found that @cynicalsally/cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Open VSX has removed three extension IDs from its malicious-extension list as the legitimate publishers they impersonated move to claim the names for themselves.

Product
Socket’s PHP and Composer support is now in Beta for all customers, with PHP reachability analysis generally available.

Product
Socket is bringing experimental protection to Firefox, scanning 97,000+ extensions in Mozilla's official directory for malware and risky updates.