Skip to main content

MissCat

Never miss a single commit.

I’ll catch ’em all, meow.

MissCat is a small CLI that watches a GitHub repository and automatically runs an AI code review whenever a new pull request or commit appears.

It watches the repository, not a single PR.

Why MissCat?

AI reviewers are useful, but somebody still has to notice that a PR changed and ask them to review it again.

MissCat does that part.

new PR
  → review

new commit
  → review again

nothing changed
  → do nothing

No webhook server.
No API keys stored by MissCat.
No repeated review of the same commit with the same profile.

Prerequisites

Before running MissCat, ensure you have:

  • Python: Python 3.9 or newer
  • Git: Configured with credentials to clone and fetch the target repository (HTTPS users using GitHub CLI can run gh auth setup-git)
  • GitHub CLI (gh): Installed and authenticated (gh auth login)
  • At least one AI reviewer CLI: Installed and authenticated:

Installation

Install MissCat with pipx:

pipx install misscat

To upgrade MissCat to the latest version:

pipx upgrade misscat

Releasing (maintainers)

Releases are published to PyPI by .github/workflows/publish.yml when a vMAJOR.MINOR.PATCH tag is pushed. It uses PyPI Trusted Publishing (OIDC), so no PyPI token is stored in GitHub secrets.

One-time setup

  1. On PyPI, add a trusted publisher for the misscat project (Project → Publishing; for a first release use "Add a pending publisher"):
    • Owner: genonfire
    • Repository: misscat
    • Workflow name: publish.yml
    • Environment name: pypi
  2. In the GitHub repository, create an environment named pypi (Settings → Environments). Recommended: add required reviewers so every release needs a manual approval, and add a tag ruleset (Settings → Rules) so only maintainers can create v* tags. A deployment tag rule alone is not enough, since it matches the tag name, not the commit.

Release procedure

  1. Check that the version is not already on PyPI (versions are immutable and cannot be re-uploaded): https://pypi.org/project/misscat/#history

  2. Bump version in pyproject.toml and __version__ in src/misscat/__init__.py (the workflow fails if they differ), then merge to master.

  3. Tag the merge commit and push the tag (the tag must equal v + the pyproject.toml version):

    git tag v1.0.1
    git push origin v1.0.1
    
  4. The workflow fails before publishing if the tagged commit is not on master, the tag is malformed, the tag does not match pyproject.toml or __version__, or python -m build / twine check fails.

  5. Confirm the release:

    pipx upgrade misscat
    misscat --version
    pip index versions misscat
    

Quick Start / First Run

Watch a repository and review new PRs using the default profile:

misscat <owner/repo>

Example:

misscat genonfire/misscat

Use a specific reviewer profile:

misscat genonfire/misscat luna

MissCat resolves luna as:

~/.config/misscat/luna.yml

Running misscat with no arguments (or misscat --help) shows usage help:

misscat --help

Repository names are canonicalized to lowercase, so Genonfire/MissCat and genonfire/misscat refer to the same local workspace and state.

Configuration

MissCat ships with a bundled default.yml inside the package, so installed copies do not depend on the source checkout or current working directory.

User configuration and persistent data are kept entirely outside the package:

  • Profiles: ~/.config/misscat/<profile>.yml
  • Per-repository state: ~/.config/misscat/<owner>__<repo>.json
  • Persistent workspace: ~/.cache/misscat/repos/<owner>/<repo>/

Directory layout:

~/.config/misscat/
├── luna.yml
├── sonnet.yml
├── genonfire__typewriter.json
└── genonfire__misscat.json

Example default.yml:

reviewer:
  # provider: claude
  # model: claude-sonnet-5-5
  # args:
  #   - --allowedTools
  #   - "Bash(gh *)"

  provider: codex
  model: gpt-6.1-sol
  args:
    - --sandbox
    - workspace-write
    - -c
    - sandbox_workspace_write.network_access=true
    - -c
    - apps._default.enabled=false
    - -c
    - model_reasoning_effort=medium

prompt: |
  Read REVIEW.md if exist and act as the 1st reviewer.
  Use the gh CLI for GitHub operations, including posting the review.

watch:
  idle: [60, 120, 180, 240, 300]
  active: [300, 240, 180, 120, 60]

review:
  include_drafts: true

Example ~/.config/misscat/luna.yml:

reviewer:
  provider: codex
  model: gpt-6-luna
  args:
    - --sandbox
    - workspace-write
    - -c
    - sandbox_workspace_write.network_access=true
    - -c
    - apps._default.enabled=false
    - -c
    - model_reasoning_effort=max

The selected local profile overrides the bundled defaults.

When creating a local profile, use default.yml as the reference and specify provider, model, and args explicitly for that reviewer CLI. Do not rely on args inherited from a different provider.

The args field under reviewer is passed to the selected reviewer CLI unchanged.

Reviewed state is stored per repository and keyed by PR, HEAD SHA, and profile. The same HEAD can therefore be reviewed again with a different profile.

Gemini (Antigravity CLI)

Gemini reviews use the Antigravity CLI (agy). Configure authentication and permissions before running MissCat.

For headless reviews, configure the Antigravity CLI settings file:

~/.gemini/antigravity-cli/settings.json

{
  "toolPermission": "proceed-in-sandbox",
  "enableTerminalSandbox": true,
  "permissions": {
    "allow": [
      "command(gh)",
      "command(git)"
    ]
  }
}

Preserve any existing settings when adding these fields. Ensure the repository workspace is trusted as appropriate.

Example reviewer profile (~/.config/misscat/gemini.yml):

reviewer:
  provider: gemini
  model: gemini-3.8-flash-low
  args:
    - --print-timeout
    - 30m

Important: In headless mode, commands requiring interactive permission approval may be automatically denied. Antigravity can still exit successfully without posting a GitHub review.

If a review finishes without appearing on GitHub, run MissCat with --loud to inspect reviewer activity and permission errors.

Avoid --dangerously-skip-permissions for routine unattended operation, as it broadly bypasses tool approval checks.

Review workspace

MissCat reviews each repository in its own persistent workspace:

~/.cache/misscat/repos/<owner>/<repo>/

The repository is cloned on first use and reused for later reviews. Before each review, MissCat prepares a clean checkout of the exact PR HEAD.

Your normal development checkout is never touched.

Requirements and limits

  • Authentication expectations:
    • Git must be able to authenticate to the target repository for clone and fetch. Existing SSH keys or Git credentials work seamlessly. If using HTTPS with GitHub CLI, configure Git helper via gh auth setup-git. MissCat never stores Git credentials.
    • GitHub CLI (gh) must be authenticated (gh auth login) with permissions to query pull requests.
    • Reviewer CLIs (claude, codex, agy) must be logged in and configured with their respective provider accounts or API keys. MissCat uses their existing credentials.
  • Trusted repository and PR warning:
    • Reviewer CLIs execute within a MissCat-managed checkout of PR-controlled files.
    • MissCat should only be used with repositories and pull requests whose code and contributors you trust.
  • One process per repository:
    • Run at most one MissCat process per repository at any given time.
    • Multiple MissCat instances or profiles pointing to the same repository would share and conflict over the same persistent workspace (~/.cache/misscat/repos/<owner>/<repo>/).

Reviewer backends

MissCat is not tied to a specific AI reviewer.

Initial backends:

  • Claude Code CLI
  • Codex CLI
  • Gemini via agy(Google Antigravity CLI)

MissCat runs the selected reviewer CLI from the root of the prepared PR checkout. The CLI can therefore discover and apply its own repository instructions, such as CLAUDE.md or AGENTS.md, while REVIEW.md defines the review behavior requested by MissCat.

MissCat does not parse or translate those instruction files.

MissCat uses the authentication already configured in the reviewer CLI. The args field under reviewer can be used for CLI-specific execution options such as tool permissions, sandbox settings, or network access.

GitHub repository and pull request access is handled through the authenticated GitHub CLI (gh).

MissCat does not manage GitHub tokens, Git credentials, or AI API keys itself.

Adaptive polling

When there are no open PRs, MissCat gradually becomes lazy:

1m → 2m → 3m → 4m → 5m → 5m ...

After review work is complete, MissCat gives the author some time to make changes, then gets increasingly impatient:

5m → 4m → 3m → 2m → 1m → 1m ...

MissCat runs one review at a time.

When a review finishes successfully, it immediately checks the repository again before sleeping. If another PR or new HEAD is waiting, it reviews that next.

If a review or workspace preparation fails, that HEAD is not marked reviewed and MissCat waits 5 minutes before checking again.

What MissCat does

  • Watches all open PRs in a repository
  • Discovers PRs created after MissCat starts
  • Detects changes by PR HEAD SHA
  • Reviews every new PR HEAD once per profile
  • Avoids duplicate reviews
  • Remembers reviewed commits across restarts
  • Uses an isolated persistent review workspace
  • Supports multiple reviewer backends

MissCat does not modify code, push commits, or merge PRs.

It watches. It catches. It reviews.

Metadata

Release files for misscat 1.0.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for misscat 1.0.0
File Size Uploaded
misscat-1.0.0.tar.gz 19.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for misscat 1.0.0
File Interpreter ABI Platform
misscat-1.0.0-py3-none-any.whl Python 3 none any Details

Total release size: 35.9 kB

Release files / misscat-1.0.0.tar.gz

Download URL misscat-1.0.0.tar.gz
Size 19.4 kB
Tags Source
SHA-256 checksum
How to use checksums
f8b0bc3f07b8dfe5e6187c0c5f55fb33ace50a929d1cefc55c48e9f7fcd0c329
BLAKE2b-256 checksum
How to use checksums
28f2013d293b82433aea4bc67eded832a6790644ca4acfdb1104e33e91108452
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.

Transparency log

Release files / misscat-1.0.0-py3-none-any.whl

Download URL misscat-1.0.0-py3-none-any.whl
Size 16.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
6b61debdbff76fac0b8fe02a21da02fe6549dcf3c9c3bb4430cd8db2cdc1a672
BLAKE2b-256 checksum
How to use checksums
eeb4289989617ca799b46eb1677a52700d462558e6aba76bb921111bf07f2ccb
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

1.0.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page