AI-powered code reviews backed by real static analysis β not just GPT with a pretty face.
Live Demo Β· Architecture Β· Report Bug Β· Request Feature
Paste any GitHub repository URL or Pull Request link. Receive a brutally honest, data-backed code review in seconds.
Most "AI code review" tools are thin wrappers that blindly dump raw code into an LLM prompt and hallucinate issues. RepoRoast works fundamentally differently:
- Runs real static analysis first: Tree-sitter parses JS, TS, TSX, and Python into concrete syntax trees (ASTs). Cyclomatic complexity, nesting depth, parameter counts, magic numbers, and dependency import graphs are computed locally with zero hallucination.
- Classifies context before grading: Evaluates whether a repository is a personal portfolio, open-source library, or production microservice. An intelligent Applicability Matrix suppresses irrelevant penalties (e.g. missing
SECURITY.mdon a student portfolio). - The AI synthesizes verified facts, not raw noise: Gemini receives structured AST metrics and token-budgeted source code. It scores categories against a strict Anchor Grading Rubric and fires across 3 parallel requests to finish in ~8 seconds.
graph LR
A[GitHub URL / PR] --> B(Noise Pruning & Tree-sitter AST)
A --> C(Zero-Shot Classifier)
B --> D[Context & Applicability Engine]
C --> D
D --> E1[Part 1: Structure & Docs]
D --> E2[Part 2: Quality & Performance]
D --> E3[Part 3: Security & Fix Plan]
E1 -->|Parallel| F[Gemini 1]
E2 -->|Parallel| G[Gemini 2]
E3 -->|Parallel| H[Gemini 3]
F & G & H --> I[Deep JSON Merge]
I --> J[Weighted Score Aggregation]
J --> K[Review Dashboard UI]
- AST Static Analysis β Parses JS, TS, and Python via Tree-sitter WASM grammars to measure cyclomatic complexity, nesting depth, and magic numbers per function.
- Dependency Graph Mapping β Identifies hub files (imported by many), orphan files (imported by none), and circular dependency chains.
- Context-Aware Classification β Detects project archetypes and applies type-specific grading weights and severity suppressions.
- Parallel LLM Chaining β Splits the review into 3 concurrent Gemini requests, dropping review times from ~25s to ~8s.
- Instant Response Caching β Hashes reviews against verified
commitShametadata to serve repeat requests in ~100ms. - PR & Diff Reviews β Paste any Pull Request URL (
github.com/owner/repo/pull/1) orbase...headcomparison for incremental diff auditing. - Auto-Fix Prompt Generator β Crafts copy-pasteable, CRED-structured prompts ready for Claude, Cursor, or ChatGPT to fix every flagged vulnerability.
- Fortified Security Defense β Fences untrusted inputs inside
<repository_data>tags, enforces strict CORS whitelisting, and applies zero-budget OOM protection against files >50KB.
| Requirement | Why It's Needed |
|---|---|
| Node.js 18+ | Runtime engine for client and server |
| Gemini API Key | Powers the AI review synthesis (free tier supported) |
| GitHub Token | (Optional) Increases GitHub API rate limits to 5,000 req/hr |
# 1. Clone the repository
git clone https://github.com/Justinvcj/RepooRoast.git
cd RepooRoast
# 2. Setup and run Backend (Terminal 1)
cd server
npm install
cp .env.example .env
npm start
# Server starts on http://localhost:3001
# 3. Setup and run Frontend (Terminal 2)
cd ../client
npm install
npm run dev
# Client starts on http://localhost:5173| Variable | Required | Default | Description |
|---|---|---|---|
GEMINI_API_KEY |
Yes | β | Primary Google AI Studio API key |
GEMINI_API_KEY_2 |
No | β | Optional secondary key for parallel request pipelines |
GEMINI_API_KEY_3 |
No | β | Optional tertiary key for parallel request pipelines |
GITHUB_TOKEN |
No | β | GitHub Personal Access Token (prevents API rate limits) |
PORT |
No | 3001 |
Express server port |
NODE_ENV |
No | development |
Runtime mode (development or production) |
| Layer | Technology |
|---|---|
| Frontend | React 19, TypeScript, Tailwind CSS, Framer Motion, Vite, OGL WebGL |
| Backend | Node.js, Express 5, Axios, Helmet, Morgan, Express-Rate-Limit |
| Static Analysis | web-tree-sitter (WASM grammars for JS, TS, TSX, Python) |
| Token Optimization | gpt-tokenizer (cl100k_base encoding) |
| AI Backbone | Google Gemini (with multi-model fallback chain) |
| Testing | Vitest with HTML reporting |
cd server
npm testTests validate Tree-sitter AST metric calculations, commit-SHA cache lifecycles, file noise pruning, JSON response parsing, and XML prompt injection boundaries.
For comprehensive details regarding AST traversal, mathematical scoring algorithms, and security sandboxing, see ARCHITECTURE.md.
Contributions are welcome! Please read CONTRIBUTING.md before submitting a pull request.
This project is licensed under the MIT License.
web-tree-sitterfor WASM AST parsing capabilities.Google Geminifor high-throughput multimodal intelligence.gpt-tokenizerfor token budget allocation.