
Research
/Security News
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
Popular npm packages keyv and cacheable compromised.
reviewflow
Advanced tools
Automated AI code reviews powered by Claude Code. Assign a reviewer on your merge request — Claude reviews the code, tracks progress in real time, and follows up when you push fixes.
Works with GitLab and GitHub out of the box.
Developer pushes code
│
▼
GitLab/GitHub webhook ──► Review server receives event
│
▼
Queue deduplicates & schedules
│
▼
Pre-built worktree ensured
(~/.reviewflow/worktrees/...)
│
▼
Claude Code dispatched in --bg mode
│
┌─────────┼─────────┐
▼ ▼ ▼
Agent 1 Agent 2 Agent N
(Archi) (Tests) (Quality)
│ │ │
└─────────┼─────────┘
▼
MCP server reports progress
│
▼
Dashboard shows live status
│
▼
Review posted on MR/PR
│
▼
Dev pushes fixes ──► Auto follow-up
(same worktree, fast-forwarded)
Each review runs a configurable set of specialized audit agents — Clean Architecture, SOLID, Testing, DDD, Code Quality, and more. Define your own agents per project to match your team's standards.
{
"agents": [
{ "name": "clean-architecture", "displayName": "Clean Archi" },
{ "name": "security", "displayName": "Security" },
{ "name": "testing", "displayName": "Testing" }
]
}
A built-in Model Context Protocol server gives Claude structured tools to report progress, manage review phases, and queue actions on discussion threads — replacing fragile text-marker parsing with typed tool calls.
| MCP Tool | Purpose |
|---|---|
get_workflow | Read current review state and agent list |
start_agent / complete_agent | Track per-agent progress |
set_phase | Advance review phases |
get_threads | Fetch MR/PR discussion threads |
add_action | Queue thread actions (resolve, reply, comment) |
Powered by p-queue with:
A WebSocket-powered dashboard shows live review progress:
The dashboard computes performance insights from your review history — no configuration needed.
Per-developer analysis across 4 categories:
| Category | What it measures |
|---|---|
| Quality | Average score, blocking issues ratio |
| Responsiveness | Review turnaround time vs team average |
| Code Volume | Additions/deletions per review |
| Iteration | First-pass quality rate (reviews without blocking issues) |
Each developer gets a level (beginner → expert), a trend (improving / stable / declining), identified strengths and weaknesses, and a title based on their strongest category (Architect, Firefighter, Workhorse, Sentinel, or Balanced).
Team-level analysis shows top performer, most improved developer, and actionable tips.
AI-powered narrative (optional): click "Generate AI Insights" to have Claude produce a written analysis with per-developer and team recommendations.
Insights are computed from the first 5 reviews onward and persist across sessions.
When a developer pushes fixes after a review, Claude automatically:
This creates an iterative review loop, not just a one-shot check.
| Feature | GitLab | GitHub |
|---|---|---|
| Webhook trigger | Reviewer assigned | Review requested or needs-review label |
| Thread actions | Resolve, reply, comment | Resolve, reply, comment |
| Auto-followup | On MR push | On PR push |
| Authentication | glab CLI (OAuth) | gh CLI (OAuth) |
No API tokens needed — both platforms use secure CLI-based OAuth.
Review behavior is defined by Claude Code skills — Markdown files in your project that tell Claude what to audit and how. Templates included for frontend, backend, and API reviews in English and French.
For contributors and curious operators — what actually happens between the webhook and the posted review.
Earlier versions of Reviewflow invoked claude -p and streamed JSON in the foreground. The server now dispatches each review as a detached background session with claude --bg. The Fastify process returns the session ID immediately and observes completion asynchronously.
Completion is detected via three independent signals in first-wins semantics:
set_phase('completed') — Claude's skill calls the MCP server when the review finishesclaude agents --json polling — every 30s, looks for completed / failed / stoppedWhichever fires first wins; the other two are cancelled. The review report is then read from <worktree>/.claude/reviews/report-<mrNumber>.md and the session is cleaned with claude stop + claude rm.
Each MR runs in its own pre-built git worktree at ~/.reviewflow/worktrees/<platform>-<slug>-<mrNumber>. This:
git checkout inside Claude no longer pollutes your working branchremoveWorktree runs on merge/close, plus a daily sweep reclaims worktrees of MRs closed >24h ago or with mtime >7 daysFull state machine: Worktree Lifecycle.
The Claude agents supervisor (long-running daemon that hosts background sessions) is probed every 60 seconds. If it dies, a detached spawn brings it back under a PID-validated file lock at ~/.reviewflow/supervisor.lock. The /health endpoint surfaces the live state and reports status: degraded when the supervisor is down — Reviewflow keeps booting, but reviews will fail fast.
Every session's token usage is parsed from the Claude transcript and persisted. A configurable monthly budget caps further dispatch and broadcasts a budget panel update over WebSocket whenever a session completes. The hourly billing audit calls claude /usage and pauses dispatch if it detects unexpected API-pool usage (the OAuth subscription is the only billing path that should be active).
npm install -g reviewflow
reviewflow init
The interactive wizard will:
For non-interactive setup: reviewflow init --yes
reviewflow start
# Dashboard at http://localhost:3847
Then configure a webhook on your GitLab/GitHub project pointing to your server.
reviewflow validate
For detailed setup, see the Quick Start Guide.
| Command | Description |
|---|---|
reviewflow init | Interactive setup wizard |
reviewflow start | Start the review server |
reviewflow stop | Stop the running daemon |
reviewflow status | Show server status |
reviewflow logs | Show daemon logs |
reviewflow validate | Validate configuration |
| Init Flag | Description |
|---|---|
-y, --yes | Accept all defaults (non-interactive) |
--skip-mcp | Skip MCP server configuration |
--show-secrets | Display full webhook secrets |
--scan-path <path> | Custom scan path (repeatable) |
| Topic | Link |
|---|---|
| Quick Start | guide/quick-start |
| Configuration Reference | reference/config |
| Project Configuration | guide/project-config |
| Review Skills Guide | guide/review-skills |
| MCP Tools Reference | reference/mcp-tools |
| Architecture | architecture |
| Worktree Lifecycle | architecture/worktree-lifecycle |
| Deployment | deployment |
| Troubleshooting | guide/troubleshooting |
| Endpoint | Method | Description |
|---|---|---|
/dashboard/ | GET | Web dashboard |
/health | GET | Health check |
/status | GET | Queue status |
/webhooks/gitlab | POST | GitLab webhook receiver |
/webhooks/github | POST | GitHub webhook receiver |
/api/reviews | GET | List reviews |
/api/reviews/cancel/:jobId | POST | Cancel a running review |
/api/insights?path= | GET | Developer & team insights |
/api/insights/generate | POST | Generate AI-powered insights via Claude |
/api/stats/recalculate | POST | Recalculate stats with optional diff backfill |
/api/version/check | GET | Check for updates |
/api/version/update | POST | Trigger self-update |
/ws | WS | Real-time progress updates |
npm run dev # Dev server with hot reload
npm test # Tests in watch mode
npm run test:ci # Tests (CI mode)
npm run typecheck # TypeScript validation
npm run lint # Biome linting
npm run verify # All checks (typecheck + lint + test)
See CONTRIBUTING.md for guidelines.
MIT — Damien Gouron
FAQs
AI-powered code review automation for GitLab/GitHub using Claude Code
The npm package reviewflow receives a total of 303 weekly downloads. As such, reviewflow popularity was classified as not popular.
We found that reviewflow demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.

Security News
/Company News
Socket has joined the new Composer and Packagist sponsorship program as a launch sponsor, supporting the team that keeps PHP's package ecosystem secure.