AI pull-request review
Ship reviewed code.
Live on GitHub in minutes.
Badger reviews every pull request for security and code quality — right inside GitHub. No servers to run, no YAML to write.
Connect your GitHub org
Authorize Badger
- Read pull requests and diffs
- Post review comments
- Nothing is written to your branches
Which repositories?
You're in the free beta
Badger is live on GitHub
What Badger does
Two reviewers on every diff
A security pass runs first, then a full code review folds those findings into one verdict — posted as a single, tidy review, never a wall of bot comments.
-
Security review, firstSecrets, injection, unsafe deserialization, auth gaps — caught before a human ever looks. Prompt-injection in the diff is treated as a finding, never an instruction.
-
Code review that reads the intentIt pulls the PR description and your CONTRIBUTING.md, then judges whether the change does what it claims — correctness, edge cases, tests — not just style.
-
Comment-only until you trust itEvery repo starts in dry-run: Badger comments, nothing blocks. Flip one switch and a REQUEST_CHANGES verdict gates the merge.
Platform support
Built for GitHub — more on the way
Badger installs as a GitHub App today. The review engine is already platform-neutral, so the rest is adapter work, not a rebuild — here's what's live and what's next.
Pricing
Free while we're in beta
Badger is free during the beta. We meter usage — one review is one pull request — so when paid plans arrive you'll already know your volume, and nothing gets charged by surprise.
- Both reviewers — security & code
- Unlimited repositories
- Dry-run & blocking mode
- Metering starts now, so you'll know your volume
- No per-developer fees
- We'll announce before anything is billed
No credit card today. We'll never charge during the beta, and we'll tell you before pricing goes live.
Good to know
Questions, answered
Does Badger store my source code?
No. It reads a pull request's diff at review time and posts comments back. Nothing is cloned, written to your branches, or kept after the review.
Will it start blocking merges on day one?
Never by surprise. Every repo begins in dry-run (comment-only). Blocking is a per-repo switch you flip when your team is ready.
Which platforms are supported?
GitHub today, as a GitHub App. GitLab, Azure Repos, Bitbucket and CircleCI are on the roadmap — the review engine is already platform-neutral, so they're adapter work rather than a rebuild.
How do I install it?
Install the Badger GitHub App on your organization, choose repositories, and you're live. Reviews start on your next pull request, in dry-run.
Can I limit it to certain repos?
Yes. "All repositories" is the fast default; narrow the list any time from settings, per organization.
What does it cost?
It's free during the beta. Usage is metered (one review = one pull request) so there are no surprises when paid plans arrive; we'll announce pricing before anything is billed.
User input flows into
os.path.joinwith no sanitizing, so?file=../../etc/passwdescapesROOT. Usesafe_join(or reject..and absolute paths) before opening the file.