AI pull-request review

Ship reviewed code.
Live on GitHub in minutes.

Badger reviews every pull request for security and code quality — right inside GitHub. No servers to run, no YAML to write.

Free while in beta — no card required.
Built for GitHub today · GitLab, Azure Repos, Bitbucket & CircleCI on the roadmap
Connect BadgerInteractive demo 0 clicks

Connect your GitHub org

Badger installs as a GitHub App. Nothing to run yourself.
GitLab, Azure Repos, Bitbucket & CircleCI are on the roadmap.

Authorize Badger

One redirect. Badger never stores your source.
GitHub
Grant read access to pick repos
  • Read pull requests and diffs
  • Post review comments
  • Nothing is written to your branches

Which repositories?

Start with everything — narrow it later in settings.
All repositoriesRecommended · 24 repos found

You're in the free beta

Every feature, unlimited repos — usage metered, never charged yet.

Badger is live on GitHub

Your next pull request gets reviewed automatically.
Connected in 4 clicks

What Badger does

Two reviewers on every diff

A security pass runs first, then a full code review folds those findings into one verdict — posted as a single, tidy review, never a wall of bot comments.

  • Security review, first
    Secrets, injection, unsafe deserialization, auth gaps — caught before a human ever looks. Prompt-injection in the diff is treated as a finding, never an instruction.
  • Code review that reads the intent
    It pulls the PR description and your CONTRIBUTING.md, then judges whether the change does what it claims — correctness, edge cases, tests — not just style.
  • Comment-only until you trust it
    Every repo starts in dry-run: Badger comments, nothing blocks. Flip one switch and a REQUEST_CHANGES verdict gates the merge.
Badger reviewed #412 · Add file download endpoint Changes requested
server/downloads.py
- 41 path = os.path.join(ROOT, request.args["file"])
+ 41 path = safe_join(ROOT, request.args["file"])
Blocker Path traversal

User input flows into os.path.join with no sanitizing, so ?file=../../etc/passwd escapes ROOT. Use safe_join (or reject .. and absolute paths) before opening the file.

Platform support

Built for GitHub — more on the way

Badger installs as a GitHub App today. The review engine is already platform-neutral, so the rest is adapter work, not a rebuild — here's what's live and what's next.

Pricing

Free while we're in beta

Badger is free during the beta. We meter usage — one review is one pull request — so when paid plans arrive you'll already know your volume, and nothing gets charged by surprise.

Beta
Free access
$0
Everything on, while Badger is in beta
  • Both reviewers — security & code
  • Unlimited repositories
  • Dry-run & blocking mode
Install on GitHub
After the beta
Pay-per-review
Planned — one credit per pull request, no seat fees
  • Metering starts now, so you'll know your volume
  • No per-developer fees
  • We'll announce before anything is billed
Beta is free

No credit card today. We'll never charge during the beta, and we'll tell you before pricing goes live.

Good to know

Questions, answered

Does Badger store my source code?

No. It reads a pull request's diff at review time and posts comments back. Nothing is cloned, written to your branches, or kept after the review.

Will it start blocking merges on day one?

Never by surprise. Every repo begins in dry-run (comment-only). Blocking is a per-repo switch you flip when your team is ready.

Which platforms are supported?

GitHub today, as a GitHub App. GitLab, Azure Repos, Bitbucket and CircleCI are on the roadmap — the review engine is already platform-neutral, so they're adapter work rather than a rebuild.

How do I install it?

Install the Badger GitHub App on your organization, choose repositories, and you're live. Reviews start on your next pull request, in dry-run.

Can I limit it to certain repos?

Yes. "All repositories" is the fast default; narrow the list any time from settings, per organization.

What does it cost?

It's free during the beta. Usage is metered (one review = one pull request) so there are no surprises when paid plans arrive; we'll announce pricing before anything is billed.