Skip to main content

FrootAI — AmpliFAI your AI Ecosystem Get Started

All Solution Plays

Play 24

AI Code Review

Medium Designed

Automated PR review with CodeQL, OWASP scanning, and inline suggestions.

Automated code review pipeline that runs on every PR. CodeQL scans for security vulnerabilities, OWASP rules check for common web app flaws, architecture validation ensures patterns are followed, and GPT-4o generates improvement suggestions as inline PR comments. Uses the builder/reviewer/tuner agent triad — builder writes code, reviewer audits it, tuner optimizes config. GitHub Actions integration runs on every push.

Architecture Pattern

CI/CD code review: CodeQL + OWASP + AI suggestions, inline PR comments

Azure Services

Azure OpenAI (gpt-4o)GitHub ActionsCodeQLAzure DevOps

DevKit (.github Agentic OS)

  • agent.md — root orchestrator with builder→reviewer→tuner handoffs
  • 3 agents — Code Review Builder (gpt-4o), Reviewer (gpt-4o-mini), Tuner (gpt-4o-mini)
  • 3 skills — deploy (103 lines), evaluate (105 lines), tune (101 lines)
  • 4 prompts — /deploy, /test, /review, /evaluate with agent routing
  • .vscode/mcp.json — FrootAI MCP with GitHub PAT + OpenAI inputs + envFile

TuneKit (AI Config)

  • config/openai.json — temp=0.1, structured JSON output
  • config/review.json — severity thresholds, OWASP rules, style checks
  • config/guardrails.json — content safety, PII detection
  • .github/workflows — PR review pipeline, auto-comment

Tuning Parameters

Severity thresholds (critical/high/medium/low)Review depth (quick/standard/deep)OWASP rule selectionStyle check rulesAuto-fix confidence threshold

Machine evidence

FrootAI evidence lifecycle

This is an internal evidence maturity label, not third-party certification, accreditation, legal compliance, or a production guarantee. Missing or expired evidence demotes automatically; catalog claims cannot promote a play.

Designed
designed
build verified
evaluation verified

This play currently has design evidence only. A runnable scenario, endpoint evaluation, and build receipts are the next contiguous gates.

Loading architecture and cost model…

Repo Intelligence

v1

A no-clone, revision-pinned map for agents and humans. Observed evidence is separated from inferred flow so the output stays useful without pretending to be a full call graph.

Indexing bounded repository evidence…