Blueprints Linted, living reference architectures for agentic systems.

Code review agent with a maintainer gate

Plans a review of a pull request, reviews files in parallel and posts comments only after a maintainer approves.

orchestrator-workers risk medium v1 software engineering seed

Why this topology

  1. autonomous-needs-consent: autonomous topology removed (autonomy is act_with_approval)
  2. open-ended-fanout: orchestrator-workers (open-ended task with parallel subtasks)

Mandatory controls: human_gate rate_limit

Flow

  1. plan → Review planner · 4000 in / 600 out
  2. review → File reviewer · 6000 in / 800 out × 8.0
Diagram source (Mermaid)
flowchart LR
    io_in(["request"])
    io_out(["response"])
    c_planner_model(["Review planner"])
    c_reviewer_model(["File reviewer"])
    c_repo_reader[["Repository reader"]]
    c_pr_commenter[["Pull request commenter"]]
    c_post_gate{{"Comment approval"}}
    g_budget>"rate_limit"]
    g_audit>"audit_log"]
    io_in --> c_planner_model
    c_planner_model --> c_reviewer_model
    c_reviewer_model --> io_out
    g_budget -.-> c_planner_model
    g_budget -.-> c_reviewer_model
    g_audit -.-> c_pr_commenter

Components

idnamekindrolemodel / tool / framework
planner-modelReview plannermodelsplit the pull request into review tasks claude-opus-5-5
reviewer-modelFile reviewermodelreview one file or one concern and propose comments claude-sonnet-5-5
repo-readerRepository readertoolread the diff and surrounding files
pr-commenterPull request commentertoolpost review comments on the pull request
post-gateComment approvalhuman_gatea maintainer approves the comments before they are posted

Guardrails

idkindprotectswhat it does
budgetrate_limitplanner-model, reviewer-modelA token and file-count cap per pull request stops runaway fan-out.
auditaudit_logpr-commenterEvery posted comment is logged with the plan step that produced it.

Failure modes

failurecomponentmitigated by
The plan skips the risky files.Review plannerpost-gate
Reviewers post many low-value or wrong comments.File reviewerpost-gate
The planner spawns far more review tasks than the change needs.Review plannerbudget

Threats

OWASPcomponentmitigated bynote
LLM01 Prompt InjectionFile reviewerpost-gatecode and comments under review can carry instructions
LLM06 Excessive AgencyPull request commenterpost-gatewrite access to the pull request
LLM10 Unbounded ConsumptionReview plannerbudgetunbounded fan-out

Eval plan

metricmethodthreshold
comment precisionmaintainers label a sample of proposed comments>= 0.7
seeded-bug recallpull requests with known injected defects>= 0.6

Observability and deployment

worker triggered by pull request events · Comments are held in a queue until approved.

Estimated cost

$0.1880 per request · $1692.00 / month at 300 requests/day · ~97.6 s end to end

Over the stated budget of $1500 per month.

Prices as of 2026-10-01 · source · latency is assumed.

Runnable starter

No starter is offered: no API data for langgraph from Radar yet.

Changelog