Skip to main content

CodeSpy logo

CodeSpy

An open-source AI reviewer that catches bugs, improves code quality, and integrates directly into your PR workflow, without sacrificing control or security.


Table of Contents


Why CodeSpy?

Most AI code reviewers are:

  • ❌ Black boxes
  • ❌ SaaS-only
  • ❌ Opaque about reasoning
  • ❌ Risky for sensitive codebases

CodeSpy is different:

  • 🔍 Transparent reasoning
  • 🔐 Self-hostable
  • 🔄 Native PR integration
  • 🧩 Extensible architecture
  • 📦 100% open-source

Built for engineering teams that care about correctness, security, and control.


Features

  • 🔒 Security Analysis — Detects common vulnerabilities (injection, auth issues, data exposure) with CWE references
  • 🐛 Bug Detection — Identifies logic errors, null references, resource leaks, edge cases
  • 📝 Documentation Review — Checks for missing docstrings, outdated comments, incomplete docs
  • 🔍 Intelligent Scope Detection — Automatically identifies code scopes (frontend, backend, infra, microservice in monorepo, etc.)
  • 🧠 Cross-Review Memory — Agents learn patterns, constants, and domain knowledge from past reviews of the same codebase
  • 💰 Cost Tracking — Track LLM calls, tokens, and costs per review
  • 🤖 Model Agnostic — Works with OpenAI, AWS Bedrock, Anthropic, Gemini, Ollama, and more via LiteLLM
  • 🐳 Docker Ready — Run locally or in the cloud with Docker
  • GitHub GitLab GitHub & GitLab — Works with both platforms, auto-detects from URL
  • 🖥️ Local Reviews — Review local git changes without GitHub/GitLab — diff against any branch, ref, or review uncommitted work
  • 🧩 MCP Server — IDE integration via Model Context Protocol — trigger reviews from AI coding assistants without leaving your editor
  • 🔌 GitHub Action — One-line integration for automatic PR reviews

Installation

Using pip

pip install codespy-ai

Using Homebrew (macOS/Linux)

brew tap khezen/codespy
brew install codespy

Using Docker

# Pull the pre-built image from GitHub Container Registry
docker pull ghcr.io/khezen/codespy:latest

# Or build locally
docker build -t codespy .

Using Poetry (for development)

# Clone the repository
git clone https://github.com/khezen/codespy.git
cd codespy

# Install dependencies
poetry install

# Or install only production dependencies
poetry install --only main

Quick Start

Get up and running in 30 seconds:

# 1. Set your Git token (or let codespy auto-discover from gh/glab CLI)
export GITHUB_TOKEN=ghp_xxxxxxxxxxxxxxxxxxxx  # For GitHub
# OR
export GITLAB_TOKEN=glpat-xxxxxxxxxxxxxxxxxxxx  # For GitLab

# 2. Set your LLM provider (example with Anthropic)
export DEFAULT_MODEL=anthropic/claude-opus-4-6
export ANTHROPIC_API_KEY=sk-ant-xxxxxxxxxxxxxxxxxxxx

# 3. Review a PR or MR!
codespy review https://github.com/owner/repo/pull/123
# OR
codespy review https://gitlab.com/group/project/-/merge_requests/123

codespy auto-discovers credentials from standard locations (~/.aws/credentials, gh auth token, glab auth token, etc.) - see Configuration for details.


Documentation

Guide Contents
Usage CLI commands, Docker, GitHub Action, MCP server, output formats
Configuration Environment variables, YAML config, model strategy, per-signature settings
Architecture Pipeline design, DSPy signatures, supported languages
Memory System Hippocampus episodic memory for cross-review knowledge
Development Setup, build, test, lint

Contributors

  • @khezen
  • @pranavsriram8

License

MIT

Metadata

Release files for codespy-ai 1.0.9

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for codespy-ai 1.0.9
File Size Uploaded
codespy_ai-1.0.9.tar.gz 160.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for codespy-ai 1.0.9
File Interpreter ABI Platform
codespy_ai-1.0.9-py3-none-any.whl Python 3 none any Details

Total release size: 379.3 kB

Release files / codespy_ai-1.0.9.tar.gz

Download URL codespy_ai-1.0.9.tar.gz
Size 160.5 kB
Tags Source
SHA-256 checksum
How to use checksums
6692bc2e5f4165a4a11929550719aaad4132a10cfe4a01386813ac074e668a50
BLAKE2b-256 checksum
How to use checksums
26cb991959e226fb99905b25cd8491637d4746e47624d524e248045ed055a4aa
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / codespy_ai-1.0.9-py3-none-any.whl

Download URL codespy_ai-1.0.9-py3-none-any.whl
Size 218.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
2a762d3d31a94bc70a3688eb96bf3eee6e5b36e9770a113d39a411f7ad5ac915
BLAKE2b-256 checksum
How to use checksums
f83a468bb6d3d0af16758f898218c2936145f1b3f4d1e2c481f01a3e1bd1ff42
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release history Release notifications | RSS feed

2.0.1

2 release files

2.0.0

2 release files

1.2.4

2 release files

1.2.3

2 release files

1.2.2

2 release files

1.2.1

2 release files

1.2.0

2 release files

1.0.14

2 release files

1.0.13

2 release files

1.0.12

2 release files

1.0.11

2 release files

1.0.10

2 release files

This release

1.0.9 This release

2 release files

1.0.8

2 release files

1.0.7

2 release files

1.0.6

2 release files

1.0.5

2 release files

1.0.4

2 release files

1.0.3

2 release files

1.0.2

2 release files

1.0.1

2 release files

1.0.0

2 release files

0.4.1

2 release files

0.4.0

2 release files

0.3.2

2 release files

0.3.1

2 release files

0.3.0

2 release files

0.2.3

2 release files

0.2.2

2 release files

0.2.1

2 release files

0.2.0

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page