Docs
User Guide
AI code review → risk triage → scan → fix → ship. Connect SCM, open a PR, get a walkthrough, triage by risk, fix in Copilot / Cursor / Claude / VS Code. Source: docs/user-guide.md.
Pricing is deferred — early access focuses on the full review integration.
1. Overview
PRSniffer is enterprise AI code review for GitHub, GitLab, Azure DevOps, and Bitbucket — walkthroughs, Change Stack, risk triage, autofix, and deep Copilot / Cursor / Claude / VS Code integration. Security scanning (secrets, SCA, SAST) sits under Settings → Advanced.
Primary nav: Triage · PR Reviews · Risk queue · Security findings · Settings.
2. End-to-end integration flow
- Sign in → /onboarding: pick SCM → connect App / OAuth → monitor repos → optional Slack
- Settings → enable Auto-review, path instructions, knowledge base, AI platforms
- Developer opens a PR on a monitored repo
- Webhook → AI walkthrough + Change Stack + risk score + comments on the PR
- Team triages in /dashboard (risk-ordered) and /reviews
- Fix via PR thread, VS Code one-click fix, or Cursor/Claude MCP tools
- Optional: auto-approve low-risk PRs; merge when ready
Tip — Full markdown walkthrough with tables lives in docs/user-guide.md §2.
3. Onboarding
After sign-in, `/onboarding` walks:
- Choose SCM provider(s): GitHub / GitLab / Azure DevOps / Bitbucket
- Connect via GitHub App install or provider OAuth / token
- Select repositories to monitor
- Connect Slack (skippable)
- Queue first review / baseline scan
Tip — Fix / Upgrade PRs need App Contents: Read & write. See docs/local-github.md.
4. Settings (review-first)
Settings mirrors a PRSniffer-like surface. Primary sections stay visible; AppSec ops collapse under Show advanced.
- AI review — auto-review, drafts, walkthrough, Change Stack, risk, auto-approve
- Path instructions & knowledge — per-path rules + org learnings
- AI platforms — Copilot, Cursor, Claude, VS Code
- Connect · Repos · Alerts · Team
- Advanced — engines, SLA, policies, SSO, scheduled scans, SBOM, jobs
In-repo config: .prsniffer.yaml (also accepts .prsniffer.yaml).
5. PR opens → review lands
- PR opened/updated on a monitored repo
- SCM webhook triggers review (GitHub pr_review / multi-SCM scm_pr_review)
- Walkthrough + Change Stack + risk + comments posted to the PR
- Optional auto-approve when risk ≤ configured max
- Open the same review at /reviews/pr?repo=owner/name&pr=123
6. Triage
- /dashboard — risk-ordered PR triage
- /reviews — all reviews · /reviews/risk — risk queue
- /findings — security findings when you need AppSec depth
7. IDE & AI agents
- VS Code — extension: local review, diagnostics, one-click fixes
- Cursor —
.cursorrules+ MCP (POST /api/v1/mcp) - Claude —
CLAUDE.md+ MCP - Copilot —
.github/copilot-instructions.md/AGENTS.md
Tip — Details: docs/ai-platforms.md, docs/mcp-server.md.
8. CLI & CI
npx prsniffer review · npx prsniffer scan. · CI: --fail-on high --policy block --upload posts findings to /findings.
GitHub Actions: .github/workflows/prsniffer.yml and docs/templates/github-actions.yml. Azure Pipelines: azure-pipelines.yml / docs/templates/azure-pipelines.yml. Set secrets PRSNIFFER_API_URL + PRSNIFFER_API_KEY. See docs/ci.md.
Tip — Install the GitHub App for PR walkthrough + inline comments. CI is the extra gate that also fills the findings dashboard.
9. Security scanning (advanced)
Secrets, SCA, SAST, and IaC remain available under Settings → Show advanced and /findings. Fix opens an issue + PR with a real file change when the App has write access.
10. Team & alerts
Invite from Settings → Team. Connect Slack / Teams under Alerts. SSO lives under Advanced — docs/sso-scim.md.
11. Honest limits
- Review quality depends on LLM keys and repo context size
- Not a full proprietary taint engine — OpenGrep + heuristics when needed
- Auto-approve is opt-in and risk-gated
- GitHub App is the richest SCM path today
- Seat billing / pricing UI is not enabled yet