Review learning & preferences
The reviewer is configurable at two levels: global defaults that apply everywhere, and per-repository overrides for repos that need a different scope. On top of that, every dismissed finding is remembered per repository, so the review noise floor drops as you use it.
Review categories
Section titled “Review categories”| Category | Checks for |
|---|---|
security |
Vulnerabilities, injection, unsafe patterns |
secrets_scanning |
Committed keys, tokens, credentials |
performance |
Hot paths, N+1s, unnecessary work |
test_coverage |
Changed code without tests |
type_safety |
Missing types, unsafe casts |
accessibility |
ARIA, contrast, keyboard access |
style |
Conventions and consistency |
ai_safety_for_agents |
Risks in code that AI agents execute |
Each is a boolean toggle; custom_focus is a free-text directive the reviewer honors on top of the enabled categories (“focus on the retry logic in the payment client”). Set defaults once for your account, then override per repo — a docs site can turn test_coverage off; a payments service can turn everything on.
Dismissal memory
Section titled “Dismissal memory”Dismissing a finding does more than hide a comment: the dismissal is stored for the repository and retrieved during future reviews of similar code. The same false positive does not follow you from PR to PR. Memory is strictly repo-scoped — dismissing a pattern in one repository never silences it in another, and a dismissal never disables a category; it calibrates one finding shape for one repo.
What to configure first
Section titled “What to configure first”- Global: turn off categories you will never act on — every disabled category is pure noise reduction.
- Per repo: add a
custom_focuswhen a repository has a known sensitive area. - Dismiss rather than ignore: an ignored warning returns next PR; a dismissed one stays gone.