Stealth PR reviewer — looks like you wrote every word.
Project description
rpr — Stealth PR Reviewer
AI-powered PR reviews that look like you wrote them. No GitHub Apps, no bots, no traces.
What It Does
- Fetches the PR diff from GitHub
- Sends it to Claude with a prompt engineered to sound like a senior engineer (not AI)
- Posts the review under your GitHub account — inline comments on specific lines
Nobody can tell the difference.
Install
| Channel | Command |
|---|---|
| pipx (recommended) | pipx install rpr |
| pip | pip install --user rpr |
| Homebrew | brew install dedev-llc/rpr/rpr |
| npm | npm install -g @dedev-llc/rpr |
| npx | npx @dedev-llc/rpr <pr-number> |
| curl | curl -fsSL https://raw.githubusercontent.com/dedev-llc/rpr/main/install.sh | bash |
All channels install the same rpr command. You'll also need:
- GitHub CLI (
gh) — install, thengh auth login - Anthropic API key —
export ANTHROPIC_API_KEY=sk-ant-...(get one) - Python 3.9+ (already required by all channels except npm/npx, which need it on PATH at runtime)
Usage
# In any git repo:
rpr 42 # Review PR #42
rpr 42 --dry-run # Preview in terminal first
rpr 42 --approve # Review + approve
rpr 42 --request-changes # Review + request changes
rpr 42 --comment-only # Post as single comment (no inline)
rpr 42 --repo owner/repo # Specify repo explicitly
rpr 42 --model claude-sonnet-4-6 # Override model
rpr 42 -v # Verbose mode (debug)
# Review depth:
rpr 42 --depth quick # Blockers & security only (fast)
rpr 42 --depth thorough # Deep: architecture, edge cases, scale
rpr 42 # Default depth (balanced)
# Self-update:
rpr update # Update to latest version
Recommended Workflow
-
Always dry-run first until you trust the output:
rpr 42 --dry-run
-
If it looks right, post it:
rpr 42
-
Optionally tweak a word or two in the posted review for your personal touch.
Review Depth
Control how deep the review goes with --depth / -d:
| Depth | Flag | What gets flagged |
|---|---|---|
| quick | -d quick |
Production bugs, security vulnerabilities, data loss risks, major architectural violations. Skips nits and style. |
| default | (omit flag) | Bugs, security, performance, error handling, concurrency, resource leaks. Skips style preferences and obvious suggestions. |
| thorough | -d thorough |
Everything in default, plus architecture fit, edge cases, naming clarity, API design, testability, and performance at scale. |
rpr 42 -d quick # Quick scan before a fast merge
rpr 42 # Standard review (default)
rpr 42 -d thorough # Critical code path — go deep
Configuration
rpr ships with sensible defaults. To override them, drop a config file at one of these paths (first match wins):
./rpr.config.json— project-local override (per-repo)~/.config/rpr/config.json— user-wide
Example (see examples/config.json):
{
"model": "claude-opus-4-6",
"max_tokens": 16000,
"max_diff_chars": 120000,
"skip_patterns": [
"*.lock",
"*.g.dart",
"*.freezed.dart"
]
}
| Key | Meaning |
|---|---|
model |
Claude model to use |
max_tokens |
Max response length |
max_diff_chars |
Truncate diffs larger than this |
skip_patterns |
Glob patterns for files to ignore (generated code, locks, etc.) |
Custom review guidelines
Inject your team's coding standards by dropping a review-guidelines.md at:
./review-guidelines.md— project-local (per-repo)~/.config/rpr/review-guidelines.md— user-wide
The contents get appended to the system prompt and the AI enforces them as if they were your personal standards. See examples/review-guidelines.md for a starter template.
How It Stays Invisible
| Concern | Solution |
|---|---|
| GitHub Actions history | None — runs locally on your machine |
| Workflow files in repo | None — no .github/workflows needed |
| Bot label on comments | None — uses your PAT via gh CLI |
| AI-sounding language | Prompt is engineered to sound human |
| Review pattern detection | Varies tone, uses informal language |
Cost
Each review costs roughly $0.01–$0.08 depending on diff size and model:
- Small PR (< 200 lines): ~$0.01
- Medium PR (200–1000 lines): ~$0.03
- Large PR (1000+ lines): ~$0.05–0.08
Tips
- Edit after posting: Tweak a word or two in your posted review for authenticity.
- Use
--dry-runliberally: Especially on important PRs. - Customize guidelines: The more specific your
review-guidelines.md, the better the reviews match your real style. - Skip generated files: Add patterns for code generators your team uses (Freezed, json_serializable, etc.) to avoid noise.
Development
git clone https://github.com/dedev-llc/rpr
cd rpr
python -m venv .venv && source .venv/bin/activate
pip install -e . # editable install — `rpr` command works from anywhere
rpr --help
Run as a module: python -m rpr 42 --dry-run
macOS gotcha: do not clone the repo into
~/Desktop(or~/Documents). macOS sets theUF_HIDDENfile flag on everything inside those App Sandbox directories, which makes Python 3.13'ssite.pyskip the editable install's.pthfile (it treats hidden-flagged files as hidden, regardless of name). The published wheel from PyPI is unaffected — this only bites editable dev installs in sandboxed dirs. Symptom:ModuleNotFoundError: No module named 'rpr'afterpip install -e .. Fix: clone to~/code/rpror somewhere outside the sandbox.
Publishing (maintainer notes)
Releases are fully automated by .github/workflows/release.yml. Merging a version bump to main publishes to PyPI, npm, and the Homebrew tap in one shot, then tags v<version> and cuts a GitHub release. Merges that don't change the version are no-ops.
Cutting a release
scripts/bump.sh 0.1.2 # updates pyproject.toml, npm/package.json, src/rpr/__init__.py
git checkout -b release/v0.1.2
git commit -am "Release v0.1.2"
gh pr create --fill # review, merge — workflow does the rest
That's it. The workflow:
- Reads the new version, fails fast if the three files disagree, skips if
v0.1.2is already tagged - Builds + uploads the sdist/wheel to PyPI via Trusted Publishing (OIDC, no token)
- Publishes
@dedev-llc/rprto npm (theprepackhook bundlessrc/rpr/*.pyintonpm/lib/) - Resolves the real PyPI sdist URL+sha256, rewrites
Formula/rpr.rbin thededev-llc/homebrew-rprtap, and pushes - Tags
v0.1.2on this repo and creates a GitHub release with auto-generated notes
Required secrets and one-time setup
NPM_TOKEN— Automation token for@dedev-llcorg publish rightsHOMEBREW_TAP_TOKEN— Fine-grained PAT,Contents: read/writeondedev-llc/homebrew-rpr- PyPI Trusted Publisher — Configured at https://pypi.org/manage/account/publishing/ with workflow
release.ymland environmentrelease releaseGitHub Environment — Repo Settings → Environments → New environment → namereleasededev-llc/homebrew-rprrepo — Must exist with a seedFormula/rpr.rbcommitted before the first run
Manual fallback (rarely needed)
If the workflow can't run for some reason, you can publish by hand. The pypi step is python -m build && twine upload dist/* (with a PyPI API token), npm publish --access public runs from the npm/ dir, and the Homebrew formula update is whatever the workflow's homebrew job does — see .github/workflows/release.yml as the canonical reference.
Project details
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file rpr-0.1.4.tar.gz.
File metadata
- Download URL: rpr-0.1.4.tar.gz
- Upload date:
- Size: 19.0 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
9a91b92d222370e29e2bc61ecce70338e191842089780d522943dc353b7cceab
|
|
| MD5 |
f017b6f191a67c3706e875399ae01747
|
|
| BLAKE2b-256 |
c8c00f08704a4ac4e87a704f88b4b12637df399cf95292cbd8de410b4a3e3986
|
Provenance
The following attestation bundles were made for rpr-0.1.4.tar.gz:
Publisher:
release.yml on dedev-llc/rpr
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
rpr-0.1.4.tar.gz -
Subject digest:
9a91b92d222370e29e2bc61ecce70338e191842089780d522943dc353b7cceab - Sigstore transparency entry: 1307447562
- Sigstore integration time:
-
Permalink:
dedev-llc/rpr@08dc9a99eaaa35b1bd918d2a000751fb17204b8a -
Branch / Tag:
refs/heads/main - Owner: https://github.com/dedev-llc
-
Access:
private
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@08dc9a99eaaa35b1bd918d2a000751fb17204b8a -
Trigger Event:
push
-
Statement type:
File details
Details for the file rpr-0.1.4-py3-none-any.whl.
File metadata
- Download URL: rpr-0.1.4-py3-none-any.whl
- Upload date:
- Size: 18.8 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
f5e73060aa867f53e666a67468e5ecf6dc9e180ce748510798a444e891b011d2
|
|
| MD5 |
341501df7f226d8d591ae49adbf650c9
|
|
| BLAKE2b-256 |
1fcd44ceb0e2304af9b1b60772d919a47abefa7738931d5f3328f8ec267fd517
|
Provenance
The following attestation bundles were made for rpr-0.1.4-py3-none-any.whl:
Publisher:
release.yml on dedev-llc/rpr
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
rpr-0.1.4-py3-none-any.whl -
Subject digest:
f5e73060aa867f53e666a67468e5ecf6dc9e180ce748510798a444e891b011d2 - Sigstore transparency entry: 1307447625
- Sigstore integration time:
-
Permalink:
dedev-llc/rpr@08dc9a99eaaa35b1bd918d2a000751fb17204b8a -
Branch / Tag:
refs/heads/main - Owner: https://github.com/dedev-llc
-
Access:
private
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@08dc9a99eaaa35b1bd918d2a000751fb17204b8a -
Trigger Event:
push
-
Statement type: