Code review agent with a maintainer gate
Plans a review of a pull request, reviews files in parallel and posts comments only after a maintainer approves.
orchestrator-workers risk medium v1 software engineering seed
Why this topology
- autonomous-needs-consent: autonomous topology removed (autonomy is act_with_approval)
- open-ended-fanout: orchestrator-workers (open-ended task with parallel subtasks)
Mandatory controls: human_gate rate_limit
Flow
- plan → Review planner · 4000 in / 600 out
- review → File reviewer · 6000 in / 800 out × 8.0
Diagram source (Mermaid)
flowchart LR
io_in(["request"])
io_out(["response"])
c_planner_model(["Review planner"])
c_reviewer_model(["File reviewer"])
c_repo_reader[["Repository reader"]]
c_pr_commenter[["Pull request commenter"]]
c_post_gate{{"Comment approval"}}
g_budget>"rate_limit"]
g_audit>"audit_log"]
io_in --> c_planner_model
c_planner_model --> c_reviewer_model
c_reviewer_model --> io_out
g_budget -.-> c_planner_model
g_budget -.-> c_reviewer_model
g_audit -.-> c_pr_commenter
Components
| id | name | kind | role | model / tool / framework |
|---|---|---|---|---|
| planner-model | Review planner | model | split the pull request into review tasks | claude-opus-5-5 |
| reviewer-model | File reviewer | model | review one file or one concern and propose comments | claude-sonnet-5-5 |
| repo-reader | Repository reader | tool | read the diff and surrounding files | |
| pr-commenter | Pull request commenter | tool | post review comments on the pull request | |
| post-gate | Comment approval | human_gate | a maintainer approves the comments before they are posted |
Guardrails
| id | kind | protects | what it does |
|---|---|---|---|
| budget | rate_limit | planner-model, reviewer-model | A token and file-count cap per pull request stops runaway fan-out. |
| audit | audit_log | pr-commenter | Every posted comment is logged with the plan step that produced it. |
Failure modes
| failure | component | mitigated by |
|---|---|---|
| The plan skips the risky files. | Review planner | post-gate |
| Reviewers post many low-value or wrong comments. | File reviewer | post-gate |
| The planner spawns far more review tasks than the change needs. | Review planner | budget |
Threats
| OWASP | component | mitigated by | note |
|---|---|---|---|
| LLM01 Prompt Injection | File reviewer | post-gate | code and comments under review can carry instructions |
| LLM06 Excessive Agency | Pull request commenter | post-gate | write access to the pull request |
| LLM10 Unbounded Consumption | Review planner | budget | unbounded fan-out |
Eval plan
| metric | method | threshold |
|---|---|---|
| comment precision | maintainers label a sample of proposed comments | >= 0.7 |
| seeded-bug recall | pull requests with known injected defects | >= 0.6 |
Observability and deployment
- traces per pull request
- comments proposed versus approved
- tokens per pull request
worker triggered by pull request events · Comments are held in a queue until approved.
Estimated cost
$0.1880 per request · $1692.00 / month at 300 requests/day · ~97.6 s end to end
Over the stated budget of $1500 per month.
Prices as of 2026-10-01 · source · latency is assumed.
- token counts per step are estimates written with the blueprint and approved by the owner, not measurements
- steps run one after another, so parallel branches make the latency an overestimate
- latency uses an assumed time to first token and output speed per model
- 30 days per month and the stated requests per day
Runnable starter
No starter is offered: no API data for langgraph from Radar yet.
Changelog
- v1: seed