Docs

User Guide

AI code review → risk triage → scan → fix → ship. Connect SCM, open a PR, get a walkthrough, triage by risk, fix in Copilot / Cursor / Claude / VS Code. Source: docs/user-guide.md.

Pricing is deferred — early access focuses on the full review integration.

1. Overview

PRSniffer is enterprise AI code review for GitHub, GitLab, Azure DevOps, and Bitbucket — walkthroughs, Change Stack, risk triage, autofix, and deep Copilot / Cursor / Claude / VS Code integration. Security scanning (secrets, SCA, SAST) sits under Settings → Advanced.

Primary nav: Triage · PR Reviews · Risk queue · Security findings · Settings.

2. End-to-end integration flow

  1. Sign in → /onboarding: pick SCM → connect App / OAuth → monitor repos → optional Slack
  2. Settings → enable Auto-review, path instructions, knowledge base, AI platforms
  3. Developer opens a PR on a monitored repo
  4. Webhook → AI walkthrough + Change Stack + risk score + comments on the PR
  5. Team triages in /dashboard (risk-ordered) and /reviews
  6. Fix via PR thread, VS Code one-click fix, or Cursor/Claude MCP tools
  7. Optional: auto-approve low-risk PRs; merge when ready

Tip — Full markdown walkthrough with tables lives in docs/user-guide.md §2.

3. Onboarding

After sign-in, `/onboarding` walks:

  1. Choose SCM provider(s): GitHub / GitLab / Azure DevOps / Bitbucket
  2. Connect via GitHub App install or provider OAuth / token
  3. Select repositories to monitor
  4. Connect Slack (skippable)
  5. Queue first review / baseline scan

Tip — Fix / Upgrade PRs need App Contents: Read & write. See docs/local-github.md.

4. Settings (review-first)

Settings mirrors a PRSniffer-like surface. Primary sections stay visible; AppSec ops collapse under Show advanced.

  • AI review — auto-review, drafts, walkthrough, Change Stack, risk, auto-approve
  • Path instructions & knowledge — per-path rules + org learnings
  • AI platforms — Copilot, Cursor, Claude, VS Code
  • Connect · Repos · Alerts · Team
  • Advanced — engines, SLA, policies, SSO, scheduled scans, SBOM, jobs

In-repo config: .prsniffer.yaml (also accepts .prsniffer.yaml).

5. PR opens → review lands

  1. PR opened/updated on a monitored repo
  2. SCM webhook triggers review (GitHub pr_review / multi-SCM scm_pr_review)
  3. Walkthrough + Change Stack + risk + comments posted to the PR
  4. Optional auto-approve when risk ≤ configured max
  5. Open the same review at /reviews/pr?repo=owner/name&pr=123

6. Triage

7. IDE & AI agents

  • VS Code — extension: local review, diagnostics, one-click fixes
  • Cursor — .cursorrules + MCP (POST /api/v1/mcp)
  • Claude — CLAUDE.md + MCP
  • Copilot — .github/copilot-instructions.md / AGENTS.md

Tip — Details: docs/ai-platforms.md, docs/mcp-server.md.

8. CLI & CI

npx prsniffer review · npx prsniffer scan. · CI: --fail-on high --policy block --upload posts findings to /findings.

GitHub Actions: .github/workflows/prsniffer.yml and docs/templates/github-actions.yml. Azure Pipelines: azure-pipelines.yml / docs/templates/azure-pipelines.yml. Set secrets PRSNIFFER_API_URL + PRSNIFFER_API_KEY. See docs/ci.md.

Tip — Install the GitHub App for PR walkthrough + inline comments. CI is the extra gate that also fills the findings dashboard.

9. Security scanning (advanced)

Secrets, SCA, SAST, and IaC remain available under Settings → Show advanced and /findings. Fix opens an issue + PR with a real file change when the App has write access.

10. Team & alerts

Invite from Settings → Team. Connect Slack / Teams under Alerts. SSO lives under Advanced — docs/sso-scim.md.

11. Honest limits

  • Review quality depends on LLM keys and repo context size
  • Not a full proprietary taint engine — OpenGrep + heuristics when needed
  • Auto-approve is opt-in and risk-gated
  • GitHub App is the richest SCM path today
  • Seat billing / pricing UI is not enabled yet