RepoPilot

io.github.MykytaStelv0.24.0更新於 Oct 2, 2026

Local, deterministic review of Git changes: weakened tests and CI gates, risky flows, blast radius.

概覽

AI 產生的概覽

RepoPilot 讓助理在本機以確定性方式審查 Git 變更,標出被削弱的測試、放寬的 CI 閘門、風險流程與影響範圍。

功能
RepoPilot 提供本機 stdio MCP 伺服器,讓代理使用其本機掃描與審查工具。它會報告關於安全邊界、行為變化、本機匯入匯出,以及依賴圖中受影響檔案的结构性證據。它也會指出變更停止執行或削弱的測試,例如被略過的測試、被移除的斷言,以及被放寬的 CI 或工具閘門。結論屬於提示性證據,指向程式碼供審查者判斷。
適用情境
適合在合併前審查變更,尤其是涉及身分驗證、請求信任、部署、相依性或密鑰設定的變更。也適合檢查編碼代理產出的工作,因為快照可標記起點,之後的審查只涵蓋此後發生的變化。它面向希望取得確定性本機證據、而非託管模型意見的開發者與團隊。
執行需求
以本機程序在使用者機器上透過 stdio 執行;僅限桌面,不是網頁可執行程式。可從 npm(repopilot)或 cargo(repopilot)安裝。未宣告身分驗證、環境變數或標頭。分析在呼叫它的機器或 CI 執行器上進行,不會把原始碼傳送到託管服務。
安裝前請注意
它在本機讀取儲存庫原始碼與 Git 歷史,因此會看到其中的內容。它不呼叫內嵌語言模型或託管服務,並且只顯示改了什麼,不顯示是誰改的。訊號僅供參考:回報的流程是待調查的路徑,並不證明可利用或安全。review、scan、baseline create 等命令會寫入報告或設定檔。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 RepoPilot,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。

其他 MCP 客戶端

參照 儲存庫 中的啟動說明。

README

RepoPilot

[Crates.io] [npm] [CI] [License]

Local, deterministic review for Git changes.

RepoPilot helps developers and teams inspect a change before merge. It reports structural evidence about security boundaries, behavior, local imports and exports, and the files affected through the dependency graph. The same review can run from a terminal, in CI, or through an agent integration.

The analysis runs on the machine or CI runner that invokes it. It does not send source to a hosted service or call an embedded language model. Findings point to code and explain what to check; reviewers still decide whether a change is safe for their application.

Example: a change that weakens its own tests

This change drops a range check from applyDiscount. The same change skips the test that would now fail, removes an assertion from another test, and lets the CI test step fail without failing the job. Every check that still runs passes. repopilot review . lists them right after its decision:

text
Decision: REVIEW (Change Proof: REVIEW)...Checks this change weakened (details under Review signals):  ⚑ check gate relaxed — .github/workflows/ci.yml:10  ⚑ assertions removed — src/pricing.test.ts:5  ⚑ test skipped — src/pricing.test.ts:9

Further down, each signal explains itself:

text
    ⚑ check gate relaxed — .github/workflows/ci.yml:10  check step `npm test` in job `test` now has `continue-on-error: true`    ⚑ assertions removed — src/pricing.test.ts:5  "applyDiscount > takes a percentage off the total": assertions 2 → 1    ⚑ test skipped — src/pricing.test.ts:9  `it.skip` added on "rejects a discount above 100%"; its result no longer fails the run

These are excerpts of one run (recording). Replay it with scripts/demo-weakened-tests.sh <empty-dir>, then run repopilot review <empty-dir>.

Install and review

bash
cargo install repopilot# ornpm install -g repopilot
repopilot review . --base origin/main

For uncommitted work, run repopilot review .. The first screen gives one PASS, REVIEW, BLOCK, or NOT ASSESSED decision, its reasons, coverage limits, and a next action.

A review can surface:

  • changes to authentication, request trust, deployment, dependencies, or secret configuration;
  • added or removed behavior such as network calls, subprocesses, filesystem writes, SQL, or error handling;
  • changed input-to-sink paths, algorithmic structure, or local import/export contracts;
  • tests the change stopped running or weakened: committed focus markers such as it.only, newly skipped tests (it.skip, @pytest.mark.skip, t.Skip, #[ignore]), removed or substituted test cases, tests that lost assertions, new lint, type, or coverage suppressions, and relaxed CI or tool gates (continue-on-error, || true, lowered coverage thresholds, strict mode off), so a green run cannot hide them;
  • direct dependents and the wider impact of changed files.

Signals are advisory evidence. For example, a taint-lite signal shows that a recognized input can reach a recognized sink in the changed source. Confirm the impact in the context of the application and its configured checks.

Example: review an image-processing change

The Wagtail example removes an authorization check and passes request data to a subprocess in a one-file change. RepoPilot reports both the boundary change and the input-to-process flow.

[RepoPilot review showing a removed authorization check and request input reaching a subprocess]

Replay the example on the pinned test repository:

bash
python3 scripts/zoo.py clone --only wagtailscripts/demo-agent-edit.sh .zoo/wagtailrepopilot review .zoo/wagtail

A reported flow is a path to investigate. RepoPilot does not prove that it is exploitable or that the application is safe.

Use in a team

Gate a branch review on high-confidence signals:

bash
repopilot review . --base origin/main --fail-on-review definitely

A review is VERIFIED only when checks configured for the repository are explicitly selected with --verify and pass on the reviewed revision. Generate suggestions for a first setup with repopilot init --suggestions-output repopilot-suggestions.toml; the file is separate from active configuration. See configuration.

For a broader repository view, run repopilot scan .. Use repopilot baseline create . to adopt existing findings before gating new work.

Agent and CI integrations

The same review can check work from a human or a coding agent. Record a starting point and review the changes made since it:

bash
repopilot snapshot# Work happens here.repopilot review --since-snapshot

When the working tree is already dirty, the marker also records a baseline commit of those uncommitted files, so the later review covers only what changed after the snapshot. It shows what changed, not who changed it. See common workflows.

In Claude Code, the RepoPilot plugin runs that loop for every session and stops Claude from finishing while a test it skipped, focused, removed, or weakened is unexplained:

text
/plugin marketplace add MykytaStel/repopilot/plugin install repopilot@repopilot

Codex installs the same plugin (codex plugin marketplace add MykytaStel/repopilot, then codex plugin add repopilot@repopilot). Gemini CLI installs it as an extension (gemini extensions install https://github.com/MykytaStel/repopilot), and Cursor runs it through project hooks. For GitHub Copilot's coding agent and other agents, RepoPilot provides setup steps, an MCP entry, and an AGENTS.md snippet. See Guard your agent runs.

RepoPilot also provides a local stdio MCP server and a GitHub Action. The MCP server gives an agent access to the local scan and review tools. The Action runs RepoPilot on the Actions runner and can publish SARIF or a pull request summary. See Guard your agent runs, MCP server, and GitHub integration. MCP Registry name: mcp-name: io.github.MykytaStel/repopilot.

More capabilities

  • repopilot ai context . creates a local handoff with repository facts, findings, and a prioritized plan. It makes no model calls.
  • repopilot init creates configuration or integration files for review.
  • Reports are available as console, Markdown, JSON, HTML, and SARIF.

Documentation

Contributing and development setup: CONTRIBUTING.md.

License

MIT OR Apache-2.0.

來源:README.md,提交 3d4b7d8

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v0.24.0最新Oct 2, 2026