Shipmoor IC · Code Review
Advisory AI code review, run locally with your own agent
Shipmoor Code Review reads your change and reports advisory findings, the kind a careful reviewer would raise. It runs on your machine with your own agent. Shipmoor hosts no model and uploads no source. One command reviews the diff, and the review never blocks your build.
- Advisory, never gates the build
- Bring your own agent, local
- No hosted model, no source upload
read → note → note → done · the review reports and exits 0; your build never waits on it.
A coding agent finishes a task and opens a pull request. The diff
compiles, but a reviewer still has to read it: an except
clause quietly swallows a failed refund and returns success, a side
effect is missing, a function is harder to follow than it should be.
This is reading-level work the deterministic scan does not try to do,
because it is judgment, not a structural fact.
Shipmoor Code Review adds that reading pass, and keeps it advisory. The deterministic scan stays the gate. Code Review is the second pair of eyes next to it, on the CLI, in your IDE, in CI, in Agent Skills, and in the Agent Harness.
- advisory only
- bring your own agent
- local review
- shipmoor.scan.v1
- SARIF
- no hosted model
- no source upload
$ shipmoor review --agent claude --from main --to HEAD
Reviewing 4 changed files (main..HEAD) · agent: claude · advisory
MEDIUM error-handling services/api/handlers/refund.py:54
the except clause swallows the error and returns 200; a failed
refund would look successful to the caller. Consider re-raising.
LOW readability services/api/handlers/refund.py:31
nested conditionals; an early return would read more clearly.
Review: 2 advisory findings · 1 medium, 1 low · exit 0 (advisory)
shipmoor.scan.v1 and SARIF written · the gate is unchanged One command reviews the change with your own agent, then reports advisory findings. The build is never blocked.
Why not just ask the agent to review?
A bare "review this diff" prompt or a loose skill produces a review that drifts. A real review pass scopes the change, pins findings to lines, and returns the same evidence format every time.
- Coverage gapsIt reads what fits the context window and skims the rest, so whole files in a large change go unread.
- Position driftFindings land on the wrong line, or no line at all, so you re-hunt the spot the model meant.
- Unstable qualityThe same diff yields a different review run to run, and nothing downstream can parse the prose.
- Scoped to the changeThe CLI scopes the diff, changed, staged, or a range, and drives the agent over the whole change, not a window of it.
- Pinned to exact linesEvery finding carries a severity and a file:line location you can jump straight to.
- Structured outputFindings come back as
shipmoor.scan.v1and SARIF, the same evidence the scan produces, machine-readable every run.
A skill makes the agent want to review. The CLI is what turns that into a complete, located, parseable review, the difference between a chat reply and a review pass.
Two engines, each doing what it's best at
Shipmoor already ships a deterministic scan that can fail the build on structural defects. Code Review is the other half: a reading pass that advises and never blocks. They stay in their own lanes.
Structural facts, the same every run
Phantom imports, hallucinated APIs, stub paths, placeholder bodies. A rule fires or it does not, an exit code you can put in front of a merge button.
enforces · can fail the buildJudgment, the soft questions
Is that the right query? Should that connection close? Does the change actually do what was asked? Your own agent reads and raises advisory findings.
advises · always exit 0A model is good at reading and bad at being a gate. So Shipmoor lets the model read and surfaces what it found, and leaves enforcement to rules that behave the same way every time.
Advisory review, not a gate
The review reports findings and exits zero, every time. Three things follow from that.
- Advisory by design It reports findings and exits zero. A second pair of eyes, not a quality gate, so it can read broadly without the risk of a false block holding up a merge.
- The scan still gates The deterministic scan is the part that can fail a build, on phantom imports, hallucinated APIs, stub paths, and placeholder bodies. Code Review sits next to it and never changes that gate.
- Your judgment decides An agent reads the change and raises advisory findings. You decide what to act on. Nothing the review surfaces can block the build on its own.
Run the review for the reading-level feedback, and keep the scan as the gate. One advises, the other enforces.
Findings pinned to the exact line
Each finding carries a severity, a rule, and a file:line
location, anchored where the change actually is, not floating in a
summary.
The except clause swallows the error and returns 200; a failed refund would look successful to the caller.
suggestre-raise after logging, or return a 5xx so the failure is visible to the caller.
advisory · this finding reports and exits 0, it does not fail the build.
The same review, native in your agent
Install the skills and the review is a step your coding agent runs itself: review the change, then fix what it surfaced, all driven by the local CLI on your machine.
- CClaude Code> /shipmoor-review reading change (advisory)… 3 findings · exit 0
- OCodex$ shipmoor review --agent codex advisory pass over diff… 2 findings · exit 0
- ⌘Cursor@shipmoor review diagnostics on changed lines… advisory · never errors
Skills make the agent run review, then fix, as one loop where the code is written. The review reads and reports; it never calls the change done on the advisory pass alone.
Bring your own agent. Shipmoor hosts no model.
Code Review never selects, builds, or hosts a model, and opens no
network boundary of its own. The review rides the agent you already
use, under your existing provider relationship. The easy path is --agent claude; any agent you can run from a command works the same way, and your
source never leaves the machine.
- claude
- codex
- cursor
- aider
- your own agent
How a review runs
Code Review is one command. It scopes to your change, asks your own agent to read it, and writes advisory findings in the same formats the scan already produces.
-
Review the working change
shipmoor review --agent claude -
Review only what the branch introduced
shipmoor review --agent claude --from main --to HEAD -
Review the staged change before a commit
shipmoor review --agent claude --staged -
Write SARIF for an advisory upload
shipmoor review --agent claude --from main --to HEAD --sarif --output review.sarif
The review reads the change and reports. It never edits your code on its own, and it never holds up a merge.
Code Review across every surface
The same advisory pass wherever it runs. Start in the CLI, then surface it in your editor, in CI, in your agent, and in the harness. The CLI is the source of truth, and the review never gates on any of them.
- cli
Command line
The fast local loop. Review the change with your own agent and read findings in your shell, before you open a pull request.
- ide
IDE diagnostics
The same findings as Information diagnostics on the changed lines, never an error squiggle, never counted in your problem totals.
- ci
PR comments
An advisory pull-request comment job on a hardened, fork-safe workflow. It posts; it never blocks the merge.
- agent skills
Review then fix
A loop your agent runs: review the change, repair what it finds, re-review, never done on the advisory pass alone.
- agent harness
In the loop
Review findings ride the local feedback loop as advisory signal, alongside the deterministic gate.
The review runs on your machine, with your model
Code Review reads the change locally and asks the agent you already run to do the reading. Shipmoor selects no model, hosts no model, and opens no network boundary of its own. No source is uploaded, and the agent call rides your own provider relationship. Findings come back as shipmoor.scan.v1 and SARIF, the same evidence formats the scan produces.
A Shipmoor IC feature
Code Review needs the cli_pro entitlement that comes with Shipmoor IC. The deterministic Community scan stays free, and the two work side by side.
- Community · free
Deterministic scan
The free structural gate that can fail a build on AI-code-integrity defects.
- Local structural scan
- Gates on phantom imports, stub paths, placeholders
- shipmoor.scan.v1 and SARIF output
- No login, no account, no source upload
- Shipmoor IC · cli_pro
Advisory Code Review
Advisory review with your own agent, across CLI, IDE, CI, Agent Skills, and the harness.
- shipmoor review --agent claude on every surface
- Advisory findings, never gates the build
- Bring your own agent, no hosted model
- shipmoor.scan.v1 and SARIF, no source upload
Add an advisory reviewer to your next agent change
Install the free CLI, sign in to Shipmoor IC, and run shipmoor review --agent claude on your change. It reads the diff with your own agent, reports advisory findings, and never blocks the build.
Get Shipmoor
Install the free CLI, then sign in to Shipmoor IC to run shipmoor review.
Code Review FAQ FAQs
Advisory review, bring your own agent, and how it differs from the gate.
Keep exploring
- Shipmoor CLI The local scanner Code Review is built on.
- CI Gate The deterministic gate that can fail a build.
- Agent Skills The review then fix loop your coding agent runs.
- Claim Check Check a change against the task it was given.
- AI code integrity The category Shipmoor is built for.
- Pricing Community, IC, Team, and Enterprise.