Set up PR review
Set up automated security PR review on a GitHub repository. Each pull request receives an AI-driven security audit with inline comments and fix suggestions.
Prerequisites
- An AISafe account with manager or higher role
- The AISafe GitHub App installed on your repository (see GitHub integration)
- A Project created for the repository
Step 1: Connect GitHub
Your organization owner connects GitHub first:
- The owner navigates to Integrations and clicks Connect GitHub.
- Authorize the AISafe GitHub App and select the repositories to include.
- Ensure the App has pull request webhook permissions for the target repository.
Step 2: Create a project
- Navigate to Projects and click New Project.
- Enter a project name and select a connected repository. Set its branch and path scope.
- Save the project.
The project represents the application formed by these repositories. It owns a living knowledge base that will accumulate context across scans.
Step 3: Enable PR review
- Open the project you created.
- Go to the PR Review tab or settings section.
- Select the repository policy and toggle Enable PR review. Save it to select this project as that repository's reviewer in this workspace.
- Configure branch and path filters and publication options for each repository. If another project already holds a repository's review selection, release it in that project first. If saving reports that the settings changed since you loaded them, somebody else saved this repository's settings first — reload the project and make your change again, so you do not overwrite theirs.
- Set External contributors. On request (the default) reviews a pull request from somebody without write access only when a team member comments
@aisafe reviewon it; Automatic reviews every pull request. On a private repository the two behave the same. To ask for a review by hand, comment@aisafe review(or/aisafe review) on the pull request — it works for anyone with write access, and AISafe adds a 👀 to the comment. GitHub repositories need the AISafe app subscribed to Issue comments and GitLab projects need the webhook's Comments trigger for this to arrive. - If branch protection requires a check, copy Required check name from the saved policy. Replace rules using the old generic AISafe check name.
PR review is now active. The next pull request against the repository will trigger an automated security review.
Step 4: Open a test PR
To verify the setup works:
- Create a branch with a harmless source change in one of the selected repositories.
- Open a pull request.
- Confirm that the check and summary identify your workspace and project. With clean summaries enabled, a clean review reports that no security findings were found.
If a pull request does not trigger a review, open the project's Setup → Webhooks tab and check Webhook deliveries. The delivery log shows whether AISafe received the PR or push event and why it was ignored, such as no project bound to the repository, a branch filter mismatch, PR review disabled, or insufficient credits. The Integrations page also shows recent webhook deliveries per VCS connection, including events that could not be matched to a project.
How comments appear
AISafe posts review comments on the specific lines of the diff, similar to a human code reviewer. Each comment includes:
- The vulnerability type and severity
- A brief explanation of the issue
- A suggested fix (code snippet where applicable)
Credit consumption
Each workspace pays for its own review attempts. Each new push or authorized request uses one included review, then costs $1 when the allowance is exhausted. A push containing several commits produces one review of its latest commit. Duplicate deliveries and internal retries reuse that attempt. Adding funds does not restart a refused review; comment @aisafe review, use Run again, or push a new commit. See Credits & billing.
Next steps
- Set up scheduled scans: add recurring full scans
- Monitor for regressions: catch reverted fixes
- PR Review: how it works: understand the capability in depth
For a PR in one repository, AISafe keeps the project's companion repositories at the same exact commits throughout the base/head comparison. The source evidence that AISafe publishes belongs to the repository that triggered the review. Details from private companion repositories stay behind AISafe access controls.