notsoham11/ai-code-reviewer-agent
0
Check out the configuration reference at https://huggingface.co/docs/hub/spaces-config-reference
๐ค AI Code Reviewer & Security Auditing Agent ๐ OverviewThe AI Code Reviewer & Security Auditing Agent is an autonomous developer tooling application that automates code quality reviews and security vulnerability remediation.Rather than relying on basic text-generation prompts, the platform integrates structured Generative AI audits with an agentic, self-correcting feedback loop. It analyzes incoming source code, scores security risks against industry standards (OWASP Top 10 & CWE guidelines), and runs an iterative tool-execution chain to verify and fix bugs before delivering clean patches.
โก Key Features
- Dual-Engine OperationsLive Gemini API Integration: Connects directly to Google's LLM engine to perform structured evaluations and live patch diffs.Instant Simulation Engine: Provides a pre-packaged offline mode allowing recruiters and users to test the multi-step agent flow without needing an API key.
- GenAI Security & Vulnerability AuditingStructured JSON Outputs: Uses strict Pydantic/JSON formatting to guarantee typed responses (Severity score $0โ100$, CWE/OWASP classification, line-by-line code flags).Grounding & RAG Attribution: Retrieves and cites relevant security rules to ground findings and eliminate hallucinations.
- Agentic Tool-Calling & Self-Correction LoopMulti-Step Pipeline: Sequentially triggers virtual tools: Static Linter $\rightarrow$ Vector RAG Documentation Search $\rightarrow$ Patch Generation Engine $\rightarrow$ Verification Test Runner.Autonomous Failure Recovery: If a generated fix fails verification, the agent captures the stack trace, feeds it back into the model, and iteratively rewrites the code patch until all unit tests pass.
- Interactive Developer WorkspaceSide-by-Side Patch Diffing: Compares vulnerable source code against remediated output with a single-click patch applicator.Exportable Audit Reports: Allows developers and hiring managers to copy markdown snippets or export complete PDF audit logs.
