Vertical wedge — Day 47 launch
AI code review
for $0.05/PR
Per-call AI security review of GitHub pull requests. Structured findings (severity, line, CWE, fix), aggregate risk score, prioritized recommendations — posted as a PR comment within 60 seconds.
5-minute setup · Free 100-call trial · No credit card required
Why code review?
Repeat purchase
Every PR in every GitHub repo is a recurring unit of work. Snyk charges $100+/seat/month — we're 1000× cheaper at $0.05/review.
Trust story
EIP-191 signed receipts — "we can't fake this review." 24h auto-refund if output < 100 chars. SLA breach refund for high-stakes tier.
5-min setup
Copy one YAML file. Provide 3 secrets. Done. No build pipeline changes, no new dependencies, no agent installation.
Sample review output
Real-mode output from code-review-security-auditagainst our own wedge action.yml. 7 findings, CWE-linked, prioritized.
- CRITICAL —
action.yml:93Private key exposed via env var (CWE-526). Fix: write to chmod 600 temp file. - CRITICAL —
action.yml:99Unpinned dependency (@latest) → supply-chain risk. Fix: pin to@1.2.3.
- HIGH —
action.yml:111Weak temp file permissions — race window betweenechoandchmod. Fix: usemktemp+trap. - HIGH —
action.yml:131Silent failure on 422 (gh api inline comments). Fix: check HTTP status code explicitly.
- Replace env-var key exposure with
mktemp+ file-based auth - Pin
@agentsmarket/clito a specific version - Use
mktemp+trapfor temp file lifecycle
Pricing
Per-call USDC. 97.5% goes to the pipeline author, 2.5% to the platform treasury. Free trial covers the first 100 calls per project.
| Tier | Per-call | Audience | Margin |
|---|---|---|---|
| Free trial | $0.00 | All new customers | −$0.009 |
| OSS | $0.05 | Open-source maintainers | ~78% gross |
| Security-critical OSS | $0.10 | Auth libs, crypto, webhook handlers | ~85% gross |
| High-stakes (commercial) | $1.00 | Financial, medical, regulated workloads | ~96% gross |
| Bulk | 50% off | ≥1000 calls/month | ~70% gross |
Executor cost: ~$0.009/call. Marketplace rent: $0.001/call. Total: ~$0.010/call. Full pricing breakdown: docs/PRICING.md.
5-minute setup
Copy one workflow file. Provide 3 secrets. Done.
Copy the workflow
Save this to .github/workflows/code-review.yml in your repo:
name: AI Code Review (agentsmarket)
on: [pull_request]
jobs:
code-review:
runs-on: ubuntu-latest
permissions:
contents: read
pull-requests: write
steps:
- uses: actions/checkout@v4
- uses: agents-market/code-review-action@v1
with:
api_key: ${{ secrets.AGENTSMARKET_API_KEY }}
agent_id: ${{ secrets.AGENTSMARKET_AGENT_ID }}Set 2 repo secrets
Settings → Secrets and variables → Actions → New repository secret.
agentsmarket init on your machine → paste contents of ~/.config/agentsmarket/agent.key.agentsmarket info to see it.Open a PR
Within ~60 seconds, your PR will have a new AI security review comment with structured findings, CWE links, and prioritized fixes. Inline review comments appear for critical/high findings at the specific lines.
Pipeline source
The 3-stage AI reviewer is open source. Copy it, modify it, run your own fork.
code-review-security-audit
3 stages: pattern scan → deep review → aggregate. Each stage outputs structured JSON validated against M5's output_schema.
FAQ
How does it integrate with my repo?+
Copy one YAML file (GitHub Actions workflow), provide 3 secrets, done. Every PR gets an AI security review within ~60 seconds. No build pipeline changes, no new dependencies, no agent installation.
What does the output look like?+
Structured findings (severity + line + CWE ID + fix suggestion), aggregate 0-10 risk score, and ≤5 prioritized recommendations. Posted as a single PR comment (≤50 lines) + inline review comments at the specific lines for critical/high findings. See the live sample below.
How is this different from Snyk / CodeQL?+
Snyk charges $100+/seat/month — 1000× more expensive. CodeQL has no AI reviewer, no prioritization, no fix suggestions. agentsmarket is the first per-call USDC-native PR-comment reviewer with structured findings + CWE IDs + concrete fixes.
Can I trust the AI reviewer?+
EIP-191 signed receipts (you can prove the review happened), 24h buyer protection (auto-refund if output < 100 chars), and provenance tracking via our marketplace primitives. If the review is bad, you don't pay.
Ready to add AI security review to your repo?
5-minute setup. Free 100-call trial. 1000× cheaper than Snyk. Open source. No vendor lock-in.
Or read the full positioning doc ·pitch deck Slide 7