
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@diff-review-system/drs
Advanced tools
Automated AI code reviews for GitHub pull requests and GitLab merge requests.
Automated AI code reviews for GitHub PRs and GitLab MRs.
DRS helps teams catch critical issues earlier with specialized review agents, unified reporting, and CI-friendly automation — all powered by Pi SDK.
unified-reviewer) in execution ordercontextCompression.thresholdPercentnpm install -g @diff-review-system/drs
This installs DRS with Pi runtime bundled — no separate runtime installation needed.
cd your-project
drs init
# Copy example env file
cp .env.example .env
# Edit .env and set:
# - GITLAB_TOKEN: Your GitLab access token (for GitLab MRs)
# - GITHUB_TOKEN: Your GitHub access token (for GitHub PRs)
# - Pi runtime runs in-process automatically (no remote server needed)
# - Provider API Key: Set the API key for your chosen model provider
# - ANTHROPIC_API_KEY for Claude models (e.g., anthropic/claude-opus-4-5-20251101)
# - ZHIPU_API_KEY for GLM models (e.g., zhipuai/glm-4.7)
# - OPENAI_API_KEY for OpenAI models (e.g., openai/gpt-4)
# - See .env.example for all supported providers
DRS CLI now loads .env automatically from your current working directory.
Note: DRS runs Pi in-process by default and does not require a remote runtime endpoint.
# Review unstaged changes
drs review-local
# Review staged changes
drs review-local --staged
# Use specific agents
drs review-local --agents security,quality
| Goal | Command |
|---|---|
| Review local unstaged changes | drs review-local |
| Review local staged changes | drs review-local --staged |
| Review GitHub PR | drs review-pr --owner <owner> --repo <repo> --pr <number> |
| Review GitLab MR | drs review-mr --project <group/repo> --mr <number> |
| Review by PR/MR URL (auto-detect platform) | drs review-url <https://.../pull/... or .../-/merge_requests/...> |
| Generate PR description | drs describe-pr --owner <owner> --repo <repo> --pr <number> |
| Generate MR description | drs describe-mr --project <group/repo> --mr <number> |
Review code locally before pushing:
# Review local changes
drs review-local
# Review specific GitLab MR
drs review-mr --project my-org/my-repo --mr 123 --post-comments
# Review GitLab MR and auto-generate a description (optionally post it)
drs review-mr --project my-org/my-repo --mr 123 --describe
drs review-mr --project my-org/my-repo --mr 123 --describe --post-description
# Review GitLab MR and generate code quality report
drs review-mr --project my-org/my-repo --mr 123 --code-quality-report gl-code-quality-report.json
# Review by PR/MR URL (auto-detect GitHub vs GitLab)
drs review-url https://github.com/octocat/hello-world/pull/456 --post-comments
drs review-url https://gitlab.com/my-org/my-repo/-/merge_requests/123 --post-comments
# Review specific GitHub PR
drs review-pr --owner octocat --repo hello-world --pr 456 --post-comments
# Review GitHub PR and auto-generate a description (optionally post it)
drs review-pr --owner octocat --repo hello-world --pr 456 --describe
drs review-pr --owner octocat --repo hello-world --pr 456 --describe --post-description
# Override base branch used for diff hints
drs review-pr --owner octocat --repo hello-world --pr 456 --base-branch release/2026-01
# Generate review JSON first, then post comments after manual review
drs review-pr --owner octocat --repo hello-world --pr 456 -o review.json
drs post-comments --input review.json --owner octocat --repo hello-world --pr 456
# Show the diff context passed to agents
drs show-changes --owner octocat --repo hello-world --pr 456
# Show diff context for a single file
drs show-changes --owner octocat --repo hello-world --pr 456 --file src/app.ts
# Show diff context using a specific base branch
drs show-changes --owner octocat --repo hello-world --pr 456 --base-branch release/2026-01
# Generate PR/MR descriptions on demand
drs describe-pr --owner octocat --repo hello-world --pr 456
drs describe-pr --owner octocat --repo hello-world --pr 456 --post-description
drs describe-mr --project my-org/my-repo --mr 123
drs describe-mr --project my-org/my-repo --mr 123 --post-description
Add to your .gitlab-ci.yml:
include:
- remote: 'https://raw.githubusercontent.com/manojlds/drs/main/src/ci/gitlab-ci.template.yml'
ai_review:
extends: .drs_review
stage: review
See GitLab CI Integration Guide for:
DRS includes a secure, pre-configured workflow at .github/workflows/pr-review.yml with built-in protection against external PR abuse.
Security Features:
safe-to-review labelQuick Setup:
Configure API Keys in repository Settings → Secrets:
ANTHROPIC_API_KEY (for Claude models), orZHIPU_API_KEY (for ZhipuAI GLM models), orOPENAI_API_KEY (for OpenAI models)Set up External PR Protection (Important!):
external-pr-reviewsafe-to-review labelSee GitHub Actions Integration Guide for:
See External PR Security Guide for:
DRS can generate GitLab-compatible code quality reports that integrate seamlessly with GitLab CI/CD. This provides an alternative (or complement) to inline MR comments.
Benefits:
When to Use:
--post-comments) for critical issues requiring discussion--code-quality-report) for comprehensive static analysis# Generate code quality report only
drs review-mr --project my-org/my-repo --mr 123 \
--code-quality-report gl-code-quality-report.json
# Use both comments and code quality report
drs review-mr --project my-org/my-repo --mr 123 \
--post-comments \
--code-quality-report gl-code-quality-report.json
Add to your .gitlab-ci.yml:
code_review:
stage: review
image: node:20-alpine
before_script:
- npm install -g @diff-review-system/drs
script:
- drs review-mr --project $CI_PROJECT_PATH --mr $CI_MERGE_REQUEST_IID
--code-quality-report gl-code-quality-report.json
artifacts:
reports:
codequality: gl-code-quality-report.json
expire_in: 1 week
only:
- merge_requests
The code quality report will appear in:
DRS generates reports in GitLab's CodeClimate-compatible format:
[
{
"description": "Query uses string concatenation. Use parameterized queries instead.",
"check_name": "drs-security",
"fingerprint": "7815696ecbf1c96e6894b779456d330e",
"severity": "blocker",
"location": {
"path": "src/api/users.ts",
"lines": { "begin": 42 }
}
}
]
Severity Mapping:
For more details, see GitLab Code Quality Documentation.
DRS runs on Pi SDK as the sole review runtime.
By default, DRS starts Pi runtime in-process:
drs review-local
DRS uses Pi in-process runtime only.
DRS uses Pi runtime wiring with markdown-based agent definitions:
.pi/
└── agents/
└── review/
├── security.md # Security specialist
├── quality.md # Code quality expert
├── style.md # Style checker
├── performance.md # Performance analyzer
└── documentation.md # Documentation reviewer
Built-in agent definitions live under .pi/agents.
Full guide: See docs/CUSTOM_AGENTS.md for complete documentation on custom agents, skills, context, per-agent tools, and configuration examples.
Create custom agents in your project:
# Create custom security agent
mkdir -p .drs/agents/security
cat > .drs/agents/security/agent.md << 'EOF'
---
description: Custom security reviewer
model: anthropic/claude-sonnet-4-5-20250929
---
You are a security expert for this specific application.
## Project-Specific Rules
[Add your custom rules here]
EOF
Add project-specific guidance to a built-in agent without replacing its prompt:
mkdir -p .drs/agents/quality
cat > .drs/agents/quality/context.md << 'EOF'
# Quality Context
- Flag functions over 200 lines as HIGH
- We use TypeORM — flag raw SQL queries
EOF
.drs/context.md is injected into every agent's prompt:
# Project Context
Node.js microservice using Express + TypeORM.
Prioritize correctness, safety, and clarity.
Add agents that don't exist in the built-in set:
mkdir -p .drs/agents/api-reviewer
cat > .drs/agents/api-reviewer/agent.md << 'EOF'
---
description: REST API contract reviewer
tools:
Read: true
Grep: true
---
Review REST API changes for backward compatibility.
EOF
Then add to config: agents: [security, quality, api-reviewer]
Edit .drs/drs.config.yaml:
review:
agents:
- unified-reviewer
- security
- quality
ignorePatterns:
- "*.test.ts"
- "*.md"
describe:
enabled: true
postDescription: false
contextCompression:
enabled: true
# Dynamic budget = thresholdPercent × model context window
thresholdPercent: 0.15
# Fallback if model context window metadata is unavailable
maxTokens: 32000
softBufferTokens: 1500
hardBufferTokens: 1000
describe:
model: zhipuai/glm-4.7
Notes:
review.describe controls auto-description when running review-mr or review-pr.--describe / --skip-describe and --post-description / --skip-post-description.describe.model is used by describe-mr/describe-pr and by review-driven descriptions.contextCompression.thresholdPercent sets a context-window-aware budget (e.g. 0.15 means 15%).contextCompression.maxTokens is the fallback cap when context window metadata is unavailable.review.agents explicitly enables deep-review agents; remove an entry to disable that agent.unified-reviewer, security, quality, style, performance, documentation.If your provider/model reports token usage but returns $0.0000 cost, you can set pricing manually.
Values are in USD per 1M tokens.
pricing:
models:
opencode/glm-5-free:
input: 0.0
output: 0.0
cacheRead: 0.0
cacheWrite: 0.0
You can also set pricing directly under pi.provider.<name>.models[].cost for custom providers.
If you define custom providers/models under pi.provider.<name>, you can set metadata used by DRS:
contextWindow: used for dynamic compression sizing when thresholdPercent is enabledmaxTokens: model output limit hintcost: token pricing override (USD per 1M tokens)compat: OpenAI compatibility overrides passed through to Pi runtime (for proxy quirks)
pi.provider.<name>.compat) to apply defaults to all modelspi.provider.<name>.models[].compat) for per-model overridespi:
provider:
my-provider:
baseUrl: "https://api.example.com/v1"
api: "openai-completions"
# apiKey accepts env var name, literal key, or !command
apiKey: "MY_PROVIDER_API_KEY"
# Optional provider-wide defaults for all models
compat:
supportsStore: false
models:
- id: "my-model"
name: "My Model"
contextWindow: 200000
maxTokens: 8192
cost:
input: 0.50
output: 1.50
cacheRead: 0.00
cacheWrite: 0.00
# Optional per-model override
compat:
supportsUsageInStreaming: false
maxTokensField: "max_tokens"
Note: For built-in providers/models, context window metadata comes from the runtime model registry.
DRS trims large diffs before sending them to models, so reviews stay within context limits.
thresholdPercent enables dynamic budgeting based on model context window.maxTokens is used as fallback when context metadata is missing.Example:
contextCompression:
enabled: true
thresholdPercent: 0.15 # 15% of model context window
maxTokens: 32000 # fallback cap
softBufferTokens: 1500
hardBufferTokens: 1000
tokenEstimateDivisor: 4
DRS auto-discovers review skills from these directories when review.paths.skills is not set:
.drs/skills (project-level overrides).agents/skills (legacy/shared project skills).pi/skills (Pi-native skills)If the same skill name exists in multiple locations, earlier paths win (.drs > .agents > .pi).
Example layout:
.drs/skills/
secure-fetch/SKILL.md # Project override (preferred)
.agents/skills/
secure-fetch/SKILL.md # Legacy/shared fallback
.pi/skills/
secure-fetch/SKILL.md # Pi-native fallback
db-indexing/SKILL.md # Additional Pi-native skill
To force a single custom skills directory, set review.paths.skills:
review:
paths:
skills: config/review-skills
Focuses on:
Reviews:
Checks:
Analyzes:
# Required (depending on platform)
GITLAB_TOKEN=glpat-xxx # For GitLab MR reviews
GITHUB_TOKEN=ghp-xxx # For GitHub PR reviews
# Provider API Keys (set the one for your chosen model provider)
ANTHROPIC_API_KEY=sk-ant-xxx # For Anthropic Claude models
ZHIPU_API_KEY=xxx # For ZhipuAI GLM models
OPENAI_API_KEY=sk-xxx # For OpenAI models
# Optional
GITLAB_URL=https://gitlab.com
REVIEW_AGENTS=security,quality,style,performance
.drs/drs.config.yaml - DRS-specific configuration.gitlab-review.yml - Alternative locationFor comprehensive local development and testing instructions, see DEVELOPMENT.md.
Quick start:
# Install dependencies
npm install
# Build
npm run build
# Run tests
npm test
# Development mode
npm run dev
Pi runtime is included as a dependency — no separate installation or server needed.
Apache-2.0
Contributions welcome! Please read the contributing guidelines first.
FAQs
Workflow-first AI code maintenance for reviews, changelogs, docs, and repository upkeep.
The npm package @diff-review-system/drs receives a total of 142 weekly downloads. As such, @diff-review-system/drs popularity was classified as not popular.
We found that @diff-review-system/drs demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.