
RepoPilot
io.github.MykytaStelv0.24.0更新于 Oct 2, 2026
Local, deterministic review of Git changes: weakened tests and CI gates, risky flows, blast radius.
概览
RepoPilot 让助手在本地确定性地审查 Git 变更,标出被削弱的测试、放宽的 CI 门禁、风险流程和影响范围。
- 功能
- RepoPilot 提供一个本地 stdio MCP 服务器,让代理使用其本地扫描与审查工具。它会报告关于安全边界、行为变化、本地导入导出以及依赖图中受影响文件的结构性证据。它还会指出变更停止运行或削弱的测试,例如被跳过的测试、被删除的断言以及被放宽的 CI 或工具门禁。结论属于提示性证据,指向代码供审查者判断。
- 适用场景
- 适合在合并前审查变更,尤其是涉及身份验证、请求信任、部署、依赖或密钥配置的变更。也适合检查编码代理产出的工作,因为快照可以标记起点,之后的审查只覆盖此后发生的变化。它面向希望获得确定性本地证据、而非托管模型意见的开发者和团队。
- 运行要求
- 作为本地进程在用户机器上通过 stdio 运行;仅限桌面,不是网页可执行程序。可从 npm(repopilot)或 cargo(repopilot)安装。未声明身份验证、环境变量或请求头。分析在调用它的机器或 CI 运行器上执行,不会把源代码发送到托管服务。
安装
在 SourceWeft 中
- 打开 控制台中的 RepoPilot,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。
其他 MCP 客户端
参照 仓库 中的启动说明。
README
RepoPilot
[Crates.io] [npm] [CI] [License]
Local, deterministic review for Git changes.
RepoPilot helps developers and teams inspect a change before merge. It reports structural evidence about security boundaries, behavior, local imports and exports, and the files affected through the dependency graph. The same review can run from a terminal, in CI, or through an agent integration.
The analysis runs on the machine or CI runner that invokes it. It does not send source to a hosted service or call an embedded language model. Findings point to code and explain what to check; reviewers still decide whether a change is safe for their application.
Example: a change that weakens its own tests
This change drops a range check from applyDiscount. The same change skips the
test that would now fail, removes an assertion from another test, and lets the
CI test step fail without failing the job. Every check that still runs passes.
repopilot review . lists them right after its decision:
Further down, each signal explains itself:
These are excerpts of one run (recording). Replay it with
scripts/demo-weakened-tests.sh <empty-dir>, then run repopilot review <empty-dir>.
Install and review
For uncommitted work, run repopilot review .. The first screen gives one
PASS, REVIEW, BLOCK, or NOT ASSESSED decision, its reasons, coverage
limits, and a next action.
A review can surface:
- changes to authentication, request trust, deployment, dependencies, or secret configuration;
- added or removed behavior such as network calls, subprocesses, filesystem writes, SQL, or error handling;
- changed input-to-sink paths, algorithmic structure, or local import/export contracts;
- tests the change stopped running or weakened: committed focus markers such as
it.only, newly skipped tests (it.skip,@pytest.mark.skip,t.Skip,#[ignore]), removed or substituted test cases, tests that lost assertions, new lint, type, or coverage suppressions, and relaxed CI or tool gates (continue-on-error,|| true, lowered coverage thresholds, strict mode off), so a green run cannot hide them; - direct dependents and the wider impact of changed files.
Signals are advisory evidence. For example, a taint-lite signal shows that a recognized input can reach a recognized sink in the changed source. Confirm the impact in the context of the application and its configured checks.
Example: review an image-processing change
The Wagtail example removes an authorization check and passes request data to a subprocess in a one-file change. RepoPilot reports both the boundary change and the input-to-process flow.
[RepoPilot review showing a removed authorization check and request input reaching a subprocess]
Replay the example on the pinned test repository:
A reported flow is a path to investigate. RepoPilot does not prove that it is exploitable or that the application is safe.
Use in a team
Gate a branch review on high-confidence signals:
A review is VERIFIED only when checks configured for the repository are
explicitly selected with --verify and pass on the reviewed revision. Generate
suggestions for a first setup with
repopilot init --suggestions-output repopilot-suggestions.toml; the file is
separate from active configuration. See configuration.
For a broader repository view, run repopilot scan .. Use
repopilot baseline create . to adopt existing findings before gating new work.
Agent and CI integrations
The same review can check work from a human or a coding agent. Record a starting point and review the changes made since it:
When the working tree is already dirty, the marker also records a baseline commit of those uncommitted files, so the later review covers only what changed after the snapshot. It shows what changed, not who changed it. See common workflows.
In Claude Code, the RepoPilot plugin runs that loop for every session and stops Claude from finishing while a test it skipped, focused, removed, or weakened is unexplained:
Codex installs the same plugin (codex plugin marketplace add MykytaStel/repopilot, then codex plugin add repopilot@repopilot). Gemini CLI installs it as an
extension (gemini extensions install https://github.com/MykytaStel/repopilot),
and Cursor runs it through project hooks. For GitHub Copilot's coding
agent and other agents, RepoPilot provides setup steps, an MCP entry, and an
AGENTS.md snippet. See Guard your agent runs.
RepoPilot also provides a local stdio MCP server and a GitHub Action. The MCP
server gives an agent access to the local scan and review tools. The Action runs
RepoPilot on the Actions runner and can publish SARIF or a pull request summary.
See Guard your agent runs, MCP server,
and GitHub integration. MCP Registry
name: mcp-name: io.github.MykytaStel/repopilot.
More capabilities
repopilot ai context .creates a local handoff with repository facts, findings, and a prioritized plan. It makes no model calls.repopilot initcreates configuration or integration files for review.- Reports are available as console, Markdown, JSON, HTML, and SARIF.
Documentation
- Install · Common workflows · CLI reference
- Current architecture · Reports and schemas · Security model
- Language support · Rules reference · Roadmap
- Latest stable release notes · Release evidence · Maintainer documentation
Contributing and development setup: CONTRIBUTING.md.
License
MIT OR Apache-2.0.
来源:README.md,提交 3d4b7d8
工具
0版本历史
1- v0.24.0最新Oct 2, 2026


