Sign In

@cynicalsally/cli

Package Overview
Dependencies
Maintainers
1
Versions
13
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@cynicalsally/cli

Brutally honest code reviews. Because 'You're absolutely right' is probably absolutely wrong.

Source
npmnpm
Version
0.3.0
Version published
Weekly downloads
117
192.5%
Maintainers
1
Weekly downloads
 
Created
Source

Cynical Sally

Cynical Sally

Brutally honest code reviews. In your terminal and your AI editor.
Because "You're absolutely right" is probably absolutely wrong.
npm i -g @cynicalsally/cli · MCP server for Claude Code, Cursor & Windsurf

Cynical Sally Verdict Sally Score npm version npm downloads MCP Registry Glama score license

Your AI pair programmer is lying to you. Sally isn't.

She's the senior engineer your code hoped it'd never meet. Scores from 0 to 10, real issues backed by evidence, and fixes you can actually use.

Works as a CLI tool and as an MCP server in Claude Code, Cursor, and Windsurf.

Sally in your terminal

Sally code review with score and issues Sally actionable fixes and verdict

Install

npm install -g @cynicalsally/cli

Or run without installing:

npx @cynicalsally/cli roast ./src/

Requirements: Node.js 18+

Privacy Notes

  • Directory scans and repo reviews send selected code to the Sally backend for analysis.
  • Only review code you are allowed to upload.
  • Sensitive files such as .env, SSH keys, certs, and common credential files are skipped, but you should still avoid scanning secrets on purpose.
  • Local reports and cached results may be written to .sally/ in your project or ~/.sally/ on your machine.
  • Add .sally/ to your .gitignore and do not commit review artifacts.
.sally/

Quick Start

# Sally auto-detects what to review
sally roast
# → staged changes? reviews those
# → unstaged changes? reviews those
# → recent commit? reviews that
# → nothing? scans the directory

# Roast a file or directory
sally roast src/utils/auth.ts
sally roast ./src/

# Roast staged changes before you commit
sally roast --staged

# Compare your branch against main
sally roast --diff main

# Deep analysis with issues + actionable fixes
sally roast ./src/ -m full_truth

# Run deep analysis in the background (OS notification when done)
sally roast ./src/ -m full_truth --bg

Roast Options

sally roast [paths...] [options]

  --staged              Review only staged git changes
  --diff <branch>       Compare against another branch (e.g., main)
  -m, --mode <mode>     "quick" (default) or "full_truth" (deep dive)
  --tone <tone>         "cynical" (default), "neutral", or "professional"
  --lang <lang>         Response language code (default: "en")
  --json                Output raw JSON (for piping or scripting)
  --fail-under <score>  Exit code 1 if quality score is below threshold
  --ci                  CI mode: compact output, exit codes
  --bg                  Run Full Truth in background, get OS notification when done

Sally's Full Suite

6 tools. Unlimited usage. The most honest code reviewer you'll ever work with — in your terminal and your AI editor.

Sally's Full Suite

Explain

sally explain

Sally reads the spaghetti someone left in your codebase and translates it into plain English. Just the cold, clear truth of what it actually does.

sally explain src/utils/auth.ts

# Pipe code directly
cat legacy-module.js | sally explain

# Explain the current directory
sally explain

Refactor

sally refactor

Before and after, side by side. Sally explains why one of them is going to haunt your 3am on-call rotation.

sally refactor src/components/Dashboard.tsx

# Refactor current directory
sally refactor

PR Review

sally review-pr

Sally reviews your PR like a senior engineer who has time, opinions, and absolutely no reason to be polite.

# Review PR #42 (requires GitHub CLI)
sally review-pr 42

# Review current branch vs main
sally review-pr

# Pipe a diff
git diff main | sally review-pr

Brainstorm

sally brainstorm

Pitch your architecture idea and Sally tells you the three ways it falls apart at scale. Cheaper than a post-mortem.

sally brainstorm "Microservices for a 2-person team?"

# Brainstorm about the current project
sally brainstorm

Frontend Review

sally frontend

Sally tells you why your component re-renders on every keystroke and why your z-index is load-bearing.

sally frontend src/components/Header.tsx

# Review all frontend code in a directory
sally frontend ./src/

Marketing Review

sally marketing

Run your copy by Sally before your customers do. They won't be this constructive about it.

sally marketing "Ship faster with AI-powered code reviews"

# Review your README and landing page copy
sally marketing README.md

Every tool accepts file paths, raw text, or piped stdin. Each includes 1 free trial, no account needed.

CI/CD Integration

Gate your pipeline on code quality:

# GitHub Actions
- name: Sally Code Review
  run: npx @cynicalsally/cli roast ./src/ --fail-under=5 --ci

--ci gives compact output with exit codes. --fail-under fails the build when the score drops below your threshold. Add --json for machine-readable output.

MCP Server

Sally works as an MCP server inside Claude Code, Cursor, and Windsurf.

Claude Code

claude mcp add cynical-sally -- npx @cynicalsally/cli mcp

Cursor

Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (per project):

{
  "mcpServers": {
    "cynical-sally": {
      "command": "npx",
      "args": ["@cynicalsally/cli", "mcp"]
    }
  }
}

Windsurf

Add to ~/.codeium/windsurf/mcp_config.json:

{
  "mcpServers": {
    "cynical-sally": {
      "command": "npx",
      "args": ["@cynicalsally/cli", "mcp"]
    }
  }
}

Available tools

MCP ToolWhat it does
sally_roastCode review with score, issues, and fixes
sally_explainExplain code with Sally's personality
sally_review_prReview PR diffs
sally_refactorRefactoring suggestions with before/after
sally_brainstormFeedback on ideas and approaches
sally_frontendFrontend/UI code review
sally_marketingMarketing copy review
sally_usageCheck quota and account status

Roast by path — the agent can call sally_roast with just paths (files or directories); Sally reads them locally and skips binaries and secret files, so the agent doesn't have to read and pass content itself.

Prompts — Sally also exposes ready-made slash-command intents (roast, review-pr, explain) in clients that surface MCP prompts.

Run sally mcp in your terminal to see setup instructions.

All Commands

CommandDescription
sally roast [paths...]Review files, directories, or git changes
sally explain [file]Explain what code actually does
sally refactor [file]Refactoring with before/after code
sally review-pr [pr]Review a PR diff
sally brainstorm "idea"Feedback on ideas and approaches
sally frontend [file]Frontend/UI code review
sally marketing "copy"Marketing copy review
sally login <email>Log in via magic link
sally logoutClear stored session
sally usageCheck your quota and account status
sally upgradeUpgrade to Sally's Full Suite
sally resultsView background review results
sally mcpMCP server setup instructions

Free to Use

90 free roasts per month, no account needed. Every premium tool includes a free trial.

sally usage     # Check your quota
sally upgrade   # Unlock the Full Suite

Privacy & Security

  • Code is transmitted over HTTPS and processed in real-time
  • No source code is stored on our servers. Ever.
  • Analysis results are tied to an anonymous device ID
  • Full Suite members can optionally link an email for account features
  • Config stored locally at ~/.sally/config.json

For full details: cynicalsally.com/privacy

Contributing

Found a bug or have a feature idea? Open an issue. Sally promises to only judge your issue title a little.

License

MIT

cynicalsally.com · npm · issues

Keywords

code-review

FAQs

Package last updated on 08 Jun 2026

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts