Live on Cloudflare Edge
🤖 Cloudflare Code Review Agent
An autonomous GitHub PR review agent built on Cloudflare Workers, Durable Objects & Workers AI, inspired by Alibaba open-code-review (OCR) and guarded by a 7-Pillar Security Harness Suite.
Webhook Ingress Endpoint:
POST https://cloudflare-code-reviewer.akshat-codes.workers.dev/webhook/github
The 7-Pillar Security Suite: REAL pillars call a live external API with no native binary required — exactly what a V8-isolate Worker can do. HEURISTIC pillars are lightweight, honest re-implementations of the named project's rule *ideas* in JS, not the actual binary (Workers can't exec native code without paid Sandboxes).
- 1. Gitleaks-pattern Secret ScanHEURISTIC — regex/entropy rules modeled on Gitleaks' public default ruleset. Blocks the PR on hardcoded API keys, tokens, and private keys.
- 2. OSV.dev Vulnerability LookupREAL — new/changed
package.json dependencies are queried live against osv.dev's public vulnerability database.
- 3. Hard-Rails File FilterHEURISTIC — Alibaba-OCR-style noise reduction (lockfiles, bundles, vendor code). Not a Semgrep integration; SAST-style reasoning happens in the LLM pass below.
- 3.5. Triage GateFREE TIER — @cf/cloudflare/clef (Cloudflare's first-party open-source decision model) judges whether this diff needs the security specialist, the quality specialist, both, or neither — a docs-only or dependency-bump PR skips the expensive committee entirely. Deterministic findings (OSV.dev, policy gate) always force a security pass regardless of what triage says.
- 4. OPA-inspired Policy GateHEURISTIC — flags changes to CI/CD workflows, auth code, or infra config, and PRs over a blast-radius file-count threshold.
- 5. Mantis-style Reachability CheckREAL context, heuristic reasoning — pulls full file content (not just the diff hunk) from the GitHub Contents API so the security model can judge whether a flaw is actually reachable.
- 6. OWASP-ASRH-style Regression CheckHEURISTIC — the Lead Arbiter is instructed to verify proposed fixes introduce no secondary vulnerabilities before posting.
- 7. OpenSSF Scorecard Supply-Chain CheckREAL — new dependencies are looked up against deps.dev's OpenSSF Scorecard data (maintenance, code review practices) via its public API.
Multi-Model Reasoning Committee:
- DeepSeek-R1 Distill (Security & Exploit Analysis) + Alibaba Qwen 2.5 Coder (Clean Syntax & Fixes), synthesized by Llama 3.3 70B — optionally proxied through Cloudflare AI Gateway for 24h caching when configured.