CodeAGENT.
From noisy static analysis to a clearer code review. A coordinated AI pipeline that turns repository findings into structured, actionable reports.
- FastAPI
- Semgrep
- Bandit
- Multi-Agent LLM
- Docker
The problem
behind the project.
Static analyzers can surface many findings across a repository. CodeAGENT brings those findings into one review workflow, using multiple LLM agents to reason over the output, reduce duplication, and explain potential fixes.
How it works.
- 01
Analyze the repository
Semgrep and Bandit produce the initial static analysis findings. A containerized FastAPI backend coordinates the workflow across the repository.
- 02
Reason over findings
Multiple LLM agents use the analyzer output as input for triage, explanations, and suggested fixes.
- 03
Structure the review
The pipeline produces deduplicated, severity-ranked JSON reports, organized by file and severity so the output can be inspected or consumed by other tools.
Engineering choices.
Ground reasoning in analysis
The LLM workflow starts from Semgrep and Bandit output, giving the review a concrete static analysis foundation.
Make evaluation reproducible
Deterministic test stubs allow the orchestration and report-generation workflow to be exercised without depending on a different model response every time.
Keep inference observable
Per-file token accounting exposes inference usage alongside structured reports, making the cost of a repository review easier to understand.
Explore the source.
The repository is the implementation reference. The illustrations on this page explain the architecture; they are not application screenshots or measured results.
- FastAPI orchestration and containerized implementation
- Structured JSON reports with per-file and per-severity breakdowns
- Deterministic test stubs and token accounting