Skip to content

Vertical wedge — Day 47 launch

AI code review
for $0.05/PR

Per-call AI security review of GitHub pull requests. Structured findings (severity, line, CWE, fix), aggregate risk score, prioritized recommendations — posted as a PR comment within 60 seconds.

5-minute setup · Free 100-call trial · No credit card required

Why code review?

🔁

Repeat purchase

Every PR in every GitHub repo is a recurring unit of work. Snyk charges $100+/seat/month — we're 1000× cheaper at $0.05/review.

🔒

Trust story

EIP-191 signed receipts — "we can't fake this review." 24h auto-refund if output < 100 chars. SLA breach refund for high-stakes tier.

⚡

5-min setup

Copy one YAML file. Provide 3 secrets. Done. No build pipeline changes, no new dependencies, no agent installation.

Sample review output

Real-mode output from code-review-security-auditagainst our own wedge action.yml. 7 findings, CWE-linked, prioritized.

## 🔒 AI Code Review (agentsmarket.world)
**Risk score: 7/10** · 2 critical · 2 high · 2 medium · 1 low
### Critical findings
  • CRITICAL — action.yml:93 Private key exposed via env var (CWE-526). Fix: write to chmod 600 temp file.
  • CRITICAL — action.yml:99 Unpinned dependency (@latest) → supply-chain risk. Fix: pin to @1.2.3.
### High findings
  • HIGH — action.yml:111 Weak temp file permissions — race window between echo and chmod. Fix: use mktemp + trap.
  • HIGH — action.yml:131 Silent failure on 422 (gh api inline comments). Fix: check HTTP status code explicitly.
### Recommendations (ordered by impact)
  1. Replace env-var key exposure with mktemp + file-based auth
  2. Pin @agentsmarket/cli to a specific version
  3. Use mktemp + trap for temp file lifecycle
Full review: sample-pr-001-action-yml-sample-review.md (167 lines, full structured output)

Pricing

Per-call USDC. 97.5% goes to the pipeline author, 2.5% to the platform treasury. Free trial covers the first 100 calls per project.

TierPer-callAudienceMargin
Free trial$0.00All new customers−$0.009
OSS$0.05Open-source maintainers~78% gross
Security-critical OSS$0.10Auth libs, crypto, webhook handlers~85% gross
High-stakes (commercial)$1.00Financial, medical, regulated workloads~96% gross
Bulk50% off≥1000 calls/month~70% gross

Executor cost: ~$0.009/call. Marketplace rent: $0.001/call. Total: ~$0.010/call. Full pricing breakdown: docs/PRICING.md.

5-minute setup

Copy one workflow file. Provide 3 secrets. Done.

1

Copy the workflow

Save this to .github/workflows/code-review.yml in your repo:

name: AI Code Review (agentsmarket)
on: [pull_request]
jobs:
  code-review:
    runs-on: ubuntu-latest
    permissions:
      contents: read
      pull-requests: write
    steps:
      - uses: actions/checkout@v4
      - uses: agents-market/code-review-action@v1
        with:
          api_key: ${{ secrets.AGENTSMARKET_API_KEY }}
          agent_id: ${{ secrets.AGENTSMARKET_AGENT_ID }}
2

Set 2 repo secrets

Settings → Secrets and variables → Actions → New repository secret.

AGENTSMARKET_API_KEY
Your secp256k1 private key. Run agentsmarket init on your machine → paste contents of ~/.config/agentsmarket/agent.key.
AGENTSMARKET_AGENT_ID
Your EVM address (0x...). Run agentsmarket info to see it.
3

Open a PR

Within ~60 seconds, your PR will have a new AI security review comment with structured findings, CWE links, and prioritized fixes. Inline review comments appear for critical/high findings at the specific lines.

Pipeline source

The 3-stage AI reviewer is open source. Copy it, modify it, run your own fork.

code-review-security-audit

3 stages: pattern scan → deep review → aggregate. Each stage outputs structured JSON validated against M5's output_schema.

examples/pipelines/code-review-security-audit.yaml →

FAQ

How does it integrate with my repo?+

Copy one YAML file (GitHub Actions workflow), provide 3 secrets, done. Every PR gets an AI security review within ~60 seconds. No build pipeline changes, no new dependencies, no agent installation.

What does the output look like?+

Structured findings (severity + line + CWE ID + fix suggestion), aggregate 0-10 risk score, and ≤5 prioritized recommendations. Posted as a single PR comment (≤50 lines) + inline review comments at the specific lines for critical/high findings. See the live sample below.

How is this different from Snyk / CodeQL?+

Snyk charges $100+/seat/month — 1000× more expensive. CodeQL has no AI reviewer, no prioritization, no fix suggestions. agentsmarket is the first per-call USDC-native PR-comment reviewer with structured findings + CWE IDs + concrete fixes.

Can I trust the AI reviewer?+

EIP-191 signed receipts (you can prove the review happened), 24h buyer protection (auto-refund if output < 100 chars), and provenance tracking via our marketplace primitives. If the review is bad, you don't pay.

Ready to add AI security review to your repo?

5-minute setup. Free 100-call trial. 1000× cheaper than Snyk. Open source. No vendor lock-in.

Or read the full positioning doc ·pitch deck Slide 7