Skip to content

Move review methodology into agent system prompt - #7

Merged
CodeDeficient merged 4 commits into
mainfrom
deterministic-review-prompt
Jul 29, 2026
Merged

CodeDeficient merged 4 commits into
mainfrom
deterministic-review-prompt

Conversation

@CodeDeficient

@CodeDeficient CodeDeficient commented Jul 29, 2026

Copy link
Copy Markdown
Owner

Why this exists

The review methodology lived in command/review.md as the command template. When the agent spawned a reviewer subagent via task(), it was told to copy the prompt verbatim — but being an LLM, it paraphrased, truncated, or rewrote it. This broke the ship cycle: the reviewer subagent received an incomplete or wrong prompt.

Design decisions

Decision: Move methodology into agent system prompt

The agent file body (agent/reviewer.md) becomes the subagent's system prompt. This is deterministic — the spawning agent cannot change or paraphrase it. The command file is slimmed to just pass the input (Input: $ARGUMENTS).

Alternatives considered:

  • Plugin tool.execute.before hook to overwrite the prompt — more complex, more failure surface
  • Keeping the prompt in the command file and telling the agent harder — already tried, doesn't work

Tradeoff: The methodology is now in the agent file, not the command file. Users who want a custom review prompt must edit agent/reviewer.md instead of command/review.md.

Decision: Remove git notes mentions from agent-facing files

The plugin and pre-push hook are infrastructure. When agents know about git notes, they try to run git notes add manually, bypassing the plugin. The fix: remove all git notes mentions from agent-facing instructions. The agent just needs to know /review <sha> before push.

What this enables

  • Deterministic review prompts — the agent cannot change the methodology
  • Cleaner agent-facing instructions — no git notes mechanism details
  • The plugin and pre-push hook remain unchanged

Risks and safeguards

Risk: Users who customized command/review.md will lose their custom prompt
Mitigation: The methodology is now in agent/reviewer.md — update that file instead


CodeAnt-AI Description

Make agent-initiated code reviews consistent and easier to start

What Changed

  • Reviewer agents now always use the complete built-in review methodology instead of relying on a copied or paraphrased prompt
  • The review command only passes the requested commit, branch, pull request, or working tree input
  • Instructions no longer expose internal review-note handling to agents
  • Agent-initiated reviews now require only the review target, such as a commit SHA

Impact

✅ Consistent review guidance
✅ Fewer incomplete subagent reviews
✅ Simpler agent-initiated reviews

💡 Usage Guide

Checking Your Pull Request

Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.

Talking to CodeAnt AI

Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:

@codeant-ai ask: Your question here

This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.

Example

@codeant-ai ask: Can you suggest a safer alternative to storing this secret?

Preserve Org Learnings with CodeAnt

You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:

@codeant-ai: Your feedback here

This helps CodeAnt AI learn and adapt to your team's coding style and standards.

Example

@codeant-ai: Do not flag unused imports.

Retrigger review

Ask CodeAnt AI to review the PR again, by typing:

@codeant-ai: review

Check Your Repository Health

To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.

The review methodology now lives in agent/reviewer.md as the system
prompt, making it deterministic — the agent cannot change or paraphrase
it. command/review.md is slimmed to just pass the input.

This prevents the spawning agent from taking liberties with the review
prompt, which was breaking the ship cycle.
@codeant-ai

codeant-ai Bot commented Jul 29, 2026

Copy link
Copy Markdown

🤖 CodeAnt AI — Review Status

Status Commit Started (UTC) Finished (UTC)
✅ Reviewed your PR 4f0fbc0 Jul 29, 2026 · 15:50 15:51

@codeant-ai

codeant-ai Bot commented Jul 29, 2026

Copy link
Copy Markdown

Thanks for using CodeAnt! 🎉

We're free for open-source projects. if you're enjoying it, help us grow by sharing.

Share on X ·
Reddit ·
LinkedIn

@codeant-ai codeant-ai Bot added the size:L This PR changes 100-499 lines, ignoring generated files label Jul 29, 2026
…prompt

$ARGUMENTS is only substituted in command templates (prompt.ts:1383-1391).
When placed in the agent system prompt (agent/reviewer.md), it's never
replaced, so commands like `git show $ARGUMENTS` expand to empty strings
in bash. Replaced with descriptive <input> placeholder; the concrete value
is delivered via the user message (command/review.md: `Input: $ARGUMENTS`).
…r prompts

Enforcement now lives in the plugin, not the prompt. Only two paths
produce an enforcement-grade review note:

1. /review <target> command path (args.command === 'review')
2. Reviewer subtask with target-only prompt (SHA, PR ref, branch)

Custom reviewer prompts (e.g. 'Review commit abc1234 for correctness...')
still run but do NOT get a review note. This is the enforcement boundary.

Prompt hardening in agent/reviewer.md is defense-in-depth only.

Adds:
- isCanonicalReviewInvocation() — pure function gating note attachment
- isTargetOnlyPrompt() — rejects multiline prose, sentences, instructions
- 13 new tests covering the exact bypass prompt from the live failure,
  /review path, target-only prompts, and rejection patterns
Adds note to Manual review section explaining that seeing only
'Input: <target>' is expected — the full methodology is in the
reviewer agent system prompt.

Updates PR description to document the canonical invocation gate
and the user-visible behavior change.
@CodeDeficient
CodeDeficient merged commit 1c972f8 into main Jul 29, 2026
@CodeDeficient
CodeDeficient deleted the deterministic-review-prompt branch July 29, 2026 18:07
CodeDeficient added a commit that referenced this pull request Jul 29, 2026
…argets

extractPrNumber now matches both #7 and PR 7 / Review PR 7.
isTargetOnlyPrompt rejects bare numeric strings like '7' before
branch-name fallback, preventing ambiguous targets from resolving
to HEAD. stripTargetSelectorPrefix no longer strips 'review pr '
prefix so PR 7 stays intact for extractPrNumber.

Adds 8 new tests:
- extractPrNumber: PR 7, Review PR 7, PR #7
- isCanonicalReviewInvocation: Review PR 7, PR 7 (true);
  bare '7', Review 7, Review branch 7 (false)
- resolveTargetSha: PR 7, Review PR 7 resolve to PR head
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L This PR changes 100-499 lines, ignoring generated files

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant