MissCat
Never miss a single commit.
I’ll catch ’em all, meow.
MissCat is a small CLI that watches a GitHub repository and automatically runs an AI code review whenever a new pull request or commit appears.
It watches the repository, not a single PR.
Why MissCat?
AI reviewers are useful, but somebody still has to notice that a PR changed and ask them to review it again.
MissCat does that part.
new PR
→ review
new commit
→ review again
nothing changed
→ do nothing
No webhook server.
No API keys stored by MissCat.
No repeated review of the same commit with the same profile.
Prerequisites
Before running MissCat, ensure you have:
- Python: Python 3.9 or newer
- Git: Configured with credentials to clone and fetch the target repository (HTTPS users using GitHub CLI can run
gh auth setup-git) - GitHub CLI (
gh): Installed and authenticated (gh auth login) - At least one AI reviewer CLI: Installed and authenticated:
- Claude Code (
claude) - Codex CLI (
codex) - Antigravity CLI (
agy) for Gemini
- Claude Code (
Installation
Install MissCat with pipx:
pipx install misscat
To upgrade MissCat to the latest version:
pipx upgrade misscat
Releasing (maintainers)
Releases are published to PyPI by .github/workflows/publish.yml when a vMAJOR.MINOR.PATCH tag is pushed. It uses PyPI Trusted Publishing (OIDC), so no PyPI token is stored in GitHub secrets.
One-time setup
- On PyPI, add a trusted publisher for the
misscatproject (Project → Publishing; for a first release use "Add a pending publisher"):- Owner:
genonfire - Repository:
misscat - Workflow name:
publish.yml - Environment name:
pypi
- Owner:
- In the GitHub repository, create an environment named
pypi(Settings → Environments). Recommended: add required reviewers so every release needs a manual approval, and add a tag ruleset (Settings → Rules) so only maintainers can createv*tags. A deployment tag rule alone is not enough, since it matches the tag name, not the commit.
Release procedure
-
Check that the version is not already on PyPI (versions are immutable and cannot be re-uploaded): https://pypi.org/project/misscat/#history
-
Bump
versioninpyproject.tomland__version__insrc/misscat/__init__.py(the workflow fails if they differ), then merge tomaster. -
Tag the merge commit and push the tag (the tag must equal
v+ thepyproject.tomlversion):git tag v1.0.1 git push origin v1.0.1
-
The workflow fails before publishing if the tagged commit is not on
master, the tag is malformed, the tag does not matchpyproject.tomlor__version__, orpython -m build/twine checkfails. -
Confirm the release:
pipx upgrade misscat misscat --version pip index versions misscat
Quick Start / First Run
Watch a repository and review new PRs using the default profile:
misscat <owner/repo>
Example:
misscat genonfire/misscat
Use a specific reviewer profile:
misscat genonfire/misscat luna
MissCat resolves luna as:
~/.config/misscat/luna.yml
Running misscat with no arguments (or misscat --help) shows usage help:
misscat --help
Repository names are canonicalized to lowercase, so Genonfire/MissCat and genonfire/misscat refer to the same local workspace and state.
Configuration
MissCat ships with a bundled default.yml inside the package, so installed copies do not depend on the source checkout or current working directory.
User configuration and persistent data are kept entirely outside the package:
- Profiles:
~/.config/misscat/<profile>.yml - Per-repository state:
~/.config/misscat/<owner>__<repo>.json - Persistent workspace:
~/.cache/misscat/repos/<owner>/<repo>/
Directory layout:
~/.config/misscat/
├── luna.yml
├── sonnet.yml
├── genonfire__typewriter.json
└── genonfire__misscat.json
Example default.yml:
reviewer:
# provider: claude
# model: claude-sonnet-5-5
# args:
# - --allowedTools
# - "Bash(gh *)"
provider: codex
model: gpt-6.1-sol
args:
- --sandbox
- workspace-write
- -c
- sandbox_workspace_write.network_access=true
- -c
- apps._default.enabled=false
- -c
- model_reasoning_effort=medium
prompt: |
Read REVIEW.md if exist and act as the 1st reviewer.
Use the gh CLI for GitHub operations, including posting the review.
watch:
idle: [60, 120, 180, 240, 300]
active: [300, 240, 180, 120, 60]
review:
include_drafts: true
Example ~/.config/misscat/luna.yml:
reviewer:
provider: codex
model: gpt-6-luna
args:
- --sandbox
- workspace-write
- -c
- sandbox_workspace_write.network_access=true
- -c
- apps._default.enabled=false
- -c
- model_reasoning_effort=max
The selected local profile overrides the bundled defaults.
When creating a local profile, use default.yml as the reference and specify provider, model, and args explicitly for that reviewer CLI. Do not rely on args inherited from a different provider.
The args field under reviewer is passed to the selected reviewer CLI unchanged.
Reviewed state is stored per repository and keyed by PR, HEAD SHA, and profile. The same HEAD can therefore be reviewed again with a different profile.
Gemini (Antigravity CLI)
Gemini reviews use the Antigravity CLI (agy). Configure authentication and permissions before running MissCat.
For headless reviews, configure the Antigravity CLI settings file:
~/.gemini/antigravity-cli/settings.json
{
"toolPermission": "proceed-in-sandbox",
"enableTerminalSandbox": true,
"permissions": {
"allow": [
"command(gh)",
"command(git)"
]
}
}
Preserve any existing settings when adding these fields. Ensure the repository workspace is trusted as appropriate.
Example reviewer profile (~/.config/misscat/gemini.yml):
reviewer:
provider: gemini
model: gemini-3.8-flash-low
args:
- --print-timeout
- 30m
Important: In headless mode, commands requiring interactive permission approval may be automatically denied. Antigravity can still exit successfully without posting a GitHub review.
If a review finishes without appearing on GitHub, run MissCat with --loud to inspect reviewer activity and permission errors.
Avoid --dangerously-skip-permissions for routine unattended operation, as it broadly bypasses tool approval checks.
Review workspace
MissCat reviews each repository in its own persistent workspace:
~/.cache/misscat/repos/<owner>/<repo>/
The repository is cloned on first use and reused for later reviews. Before each review, MissCat prepares a clean checkout of the exact PR HEAD.
Your normal development checkout is never touched.
Requirements and limits
- Authentication expectations:
- Git must be able to authenticate to the target repository for clone and fetch. Existing SSH keys or Git credentials work seamlessly. If using HTTPS with GitHub CLI, configure Git helper via
gh auth setup-git. MissCat never stores Git credentials. - GitHub CLI (
gh) must be authenticated (gh auth login) with permissions to query pull requests. - Reviewer CLIs (
claude,codex,agy) must be logged in and configured with their respective provider accounts or API keys. MissCat uses their existing credentials.
- Git must be able to authenticate to the target repository for clone and fetch. Existing SSH keys or Git credentials work seamlessly. If using HTTPS with GitHub CLI, configure Git helper via
- Trusted repository and PR warning:
- Reviewer CLIs execute within a MissCat-managed checkout of PR-controlled files.
- MissCat should only be used with repositories and pull requests whose code and contributors you trust.
- One process per repository:
- Run at most one MissCat process per repository at any given time.
- Multiple MissCat instances or profiles pointing to the same repository would share and conflict over the same persistent workspace (
~/.cache/misscat/repos/<owner>/<repo>/).
Reviewer backends
MissCat is not tied to a specific AI reviewer.
Initial backends:
- Claude Code CLI
- Codex CLI
- Gemini via agy(Google Antigravity CLI)
MissCat runs the selected reviewer CLI from the root of the prepared PR checkout. The CLI can therefore discover and apply its own repository instructions, such as CLAUDE.md or AGENTS.md, while REVIEW.md defines the review behavior requested by MissCat.
MissCat does not parse or translate those instruction files.
MissCat uses the authentication already configured in the reviewer CLI.
The args field under reviewer can be used for CLI-specific execution options such as tool permissions, sandbox settings, or network access.
GitHub repository and pull request access is handled through the authenticated GitHub CLI (gh).
MissCat does not manage GitHub tokens, Git credentials, or AI API keys itself.
Adaptive polling
When there are no open PRs, MissCat gradually becomes lazy:
1m → 2m → 3m → 4m → 5m → 5m ...
After review work is complete, MissCat gives the author some time to make changes, then gets increasingly impatient:
5m → 4m → 3m → 2m → 1m → 1m ...
MissCat runs one review at a time.
When a review finishes successfully, it immediately checks the repository again before sleeping. If another PR or new HEAD is waiting, it reviews that next.
If a review or workspace preparation fails, that HEAD is not marked reviewed and MissCat waits 5 minutes before checking again.
What MissCat does
- Watches all open PRs in a repository
- Discovers PRs created after MissCat starts
- Detects changes by PR HEAD SHA
- Reviews every new PR HEAD once per profile
- Avoids duplicate reviews
- Remembers reviewed commits across restarts
- Uses an isolated persistent review workspace
- Supports multiple reviewer backends
MissCat does not modify code, push commits, or merge PRs.
It watches. It catches. It reviews.
Metadata
Release files for misscat 1.0.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| misscat-1.0.0.tar.gz | 19.4 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| misscat-1.0.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 35.9 kB
Release files / misscat-1.0.0.tar.gz
| Download URL | misscat-1.0.0.tar.gz |
|---|---|
| Size | 19.4 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
f8b0bc3f07b8dfe5e6187c0c5f55fb33ace50a929d1cefc55c48e9f7fcd0c329
|
|
BLAKE2b-256 checksum How to use checksums |
28f2013d293b82433aea4bc67eded832a6790644ca4acfdb1104e33e91108452
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.
Transparency logRelease files / misscat-1.0.0-py3-none-any.whl
| Download URL | misscat-1.0.0-py3-none-any.whl |
|---|---|
| Size | 16.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
6b61debdbff76fac0b8fe02a21da02fe6549dcf3c9c3bb4430cd8db2cdc1a672
|
|
BLAKE2b-256 checksum How to use checksums |
eeb4289989617ca799b46eb1677a52700d462558e6aba76bb921111bf07f2ccb
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.
Transparency log