repopilot_review_change
Review a Git change locally to identify weakened tests, CI gates, and security boundaries. Returns a JSON report with findings, blast radius, and confidence-tiered signals.
Instructions
Review a Git change locally: what it touched and which checks it weakened. Use it before finishing work or before a merge. By default it reviews uncommitted work (working tree vs HEAD); pass base (e.g. "origin/main") to review a branch. For a repository health check that is not about one change, use repopilot_scan instead. Returns a JSON report with a decision, findings on changed lines vs the rest, blast radius (files that import the changed files), and deterministic signals grouped by confidence tier (definitely / maybe / noise) in tiered_signals: checks the change weakened (focused or skipped tests, removed tests, tests that lost assertions, new lint/type/coverage suppressions, relaxed CI or tool gates); security-boundary changes (auth, CORS, CI, dependency manifests, committed .env); behavioral changes (network, subprocess, filesystem, env, dependency, migration, or raw SQL added; error handling, an auth check, or a test removed; a removed named TypeScript/JavaScript export that a resolved local caller still imports); algorithmic changes (deeper nesting, a new nested loop, a grown function, new recursion); and taint-lite reachability (HTTP request or process arguments reaching SQL, exec, filesystem-write, or outbound-network sinks in a changed function). Signals are evidence, not verdicts; explain one with repopilot_explain_review_signal. RepoPilot uploads nothing. Only a non-empty verify array runs commands: the configured local checks, which may modify workspace files or contact external systems. Their captured output is bounded and redacted.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| base | No | Base Git ref to diff against, e.g. "origin/main". Optional; defaults to the working tree vs HEAD. | |
| head | No | Head Git ref. Optional and only valid together with "base". | |
| path | No | Repository path to review. Defaults to the current working directory. | |
| limit | No | Maximum findings to return. | |
| scope | No | "changed" reports findings in the changed files only; "full" also returns findings from the rest of the repository. | changed |
| config | No | Optional repopilot.toml path. Defaults to the one discovered in the repository. | |
| detail | No | "compact" returns at most 20 findings and 20 signals; "full" returns all of them. | compact |
| intent | No | Optional inline statement of what the change is meant to touch (paths, contract families, critical paths, verification IDs). The report marks drift outside it. It is metadata only and cannot execute commands. | |
| offset | No | Zero-based finding offset. | |
| verify | No | IDs of checks configured in repopilot.toml to run on the reviewed revision. They run as local processes. Omit to run nothing. | |
| filters | No | Optional thresholds and rule IDs that narrow the returned findings. | |
| profile | No | "default" hides low-signal suggestions; "strict" shows all findings. | default |
| baseline | No | Optional baseline file (from `repopilot baseline create`). Findings recorded in it count as accepted debt, separate from new findings. | |
| intent_path | No | Optional repository-rooted TOML file that states what the change is meant to touch. The report marks drift outside it. Use either this or `intent`, not both. | |
| fail_on_review | No | "definitely" fails the report's gate when a gate-eligible definitely-tier signal is present; "none" reports signals without gating. | none |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||