Subsystem 01
GitHub webhook receiver
Receives pull_request events, changed files and diffs
Typical stack
FastAPI + Octokit
Reference architecture
Automated pull request review that catches injection risks, leaked secrets and architectural anti-patterns before a human reviewer starts.
Design constraints
Targets for the scenario this reference is sized for. A real engagement starts by replacing them with your own numbers.
Component topology
Subsystems with separate responsibilities, clear contracts between them and storage that scales on its own. The stack named for each is typical, not mandatory.
Stack topology
Automated code review and security scanner AI agent
Illustrative reference architecture
GitHub webhook receiver
Receives pull_request events, changed files and diffs
FastAPI + Octokit
Static analysis (SAST) scanner
Deterministic vulnerability and secret scanning
Semgrep + TruffleHog
Semantic code reviewer
Reviews architectural patterns, race conditions and test coverage
Claude API / self-hosted code model
PR comment bot
Posts actionable review comments with suggested changes
GitHub App
Subsystem 01
Receives pull_request events, changed files and diffs
Typical stack
FastAPI + Octokit
Subsystem 02
Deterministic vulnerability and secret scanning
Typical stack
Semgrep + TruffleHog
Subsystem 03
Reviews architectural patterns, race conditions and test coverage
Typical stack
Claude API / self-hosted code model
Subsystem 04
Posts actionable review comments with suggested changes
Typical stack
GitHub App
Data lifecycle
A developer opens a pull request; the webhook sends the payload to the FastAPI review dispatcher.
The scanner fetches the diff and runs Semgrep for known vulnerabilities and TruffleHog for leaked secrets.
Changed files and related context are packaged into an AST-aware review prompt.
The LLM reviews the change against the team's architecture decision records (ADRs) and style guides.
The bot posts inline review comments with one-click 'Apply suggestion' blocks.
Reliability and resilience
Failure mode 01
Mitigation
Strict confidence thresholds (above 90%), with comments limited to security, correctness and performance.
Failure mode 02
Mitigation
Skip generated files (lockfiles, minified bundles) and review large PRs in chunked passes.
Failure mode 03
Mitigation
Zero-data-retention enterprise API endpoints, or self-hosted models inside a private VPC.
Questions
Yes. It formats fixes with GitHub's suggestion syntax, so a developer can commit one with a single click.
We index your architecture decision records (ADRs) and coding standards and supply the relevant ones as context in each review prompt.
Send us your requirements, expected load and budget. We'll reply within one business day with an honest read on the design, and on whether we're the right team to build it.