← Back to dashboard
coderabbittoolingfreshReader view (for NotebookLM)

CodeRabbit Integration Guide

What is CodeRabbit?

The real model

A review gate, not a model provider — and its output is untrusted input.

CodeRabbit never appears in an AI routing table: it consumes no ANTHROPIC_API_KEY and serves no inference to your app. It sits beside gitleaks and Semgrep as a gate. The seam that matters is `cr --agent`, which emits structured JSON — the Claude Code plugin consumes that behind /coderabbit:review, closing an implement → review → fix loop inside one session. Note two traps: untracked files are excluded unless you pass --include-untracked, and a review uploads your diff, so gitleaks runs first or a committed secret becomes a disclosed one. The security point that matters most: a review comment is text derived from a diff, and on a fork PR that diff came from outside your org. CodeRabbit's own autofix skill refuses to execute reviewer-supplied prompts. Read findings as data, approve fixes one at a time.

Six CodeRabbit primitives

Four surfaces, one config file, and one machine-readable seam that ties it into an agent loop.

Text
 ██████╗ ██████╗ ██████╗ ███████╗██████╗  █████╗ ██████╗ ██████╗ ██╗████████╗
██╔════╝██╔═══██╗██╔══██╗██╔════╝██╔══██╗██╔══██╗██╔══██╗██╔══██╗██║╚══██╔══╝
██║     ██║   ██║██║  ██║█████╗  ██████╔╝███████║██████╔╝██████╔╝██║   ██║
██║     ██║   ██║██║  ██║██╔══╝  ██╔══██╗██╔══██║██╔══██╗██╔══██╗██║   ██║
╚██████╗╚██████╔╝██████╔╝███████╗██║  ██║██║  ██║██████╔╝██████╔╝██║   ██║
 ╚═════╝ ╚═════╝ ╚═════╝ ╚══════╝╚═╝  ╚═╝╚═╝  ╚═╝╚═════╝ ╚═════╝ ╚═╝   ╚═╝

CodeRabbit Integration Guide

Focus — wiring CodeRabbit's AI review into codeAmani's workflow at the point it pays off most: before the PR exists, from inside Claude Code, via the CLI and plugin.

Overview

CodeRabbit reviews code changes and posts context-aware feedback. Unlike most entries in this stack it is not an AI provider — you never route inference through it, and it does not belong in the CLAUDE.md AI Routing Policy table. It is a reviewer: you hand it a diff, it hands back findings.

The thing worth internalising is that CodeRabbit has four independent surfaces, and they review different things at different moments:

SurfaceReviewsWhen
Platform (PR reviews)The pushed branch diffAfter you open a PR
CLI (cr)Local, uncommitted changesBefore you commit
IDE extensionWorking-tree changes in-editorWhile you type (VS Code, Cursor, Windsurf)
AgentConversation contextIn Slack / Discord

For an agentic workflow the CLI is the one that matters — it is the only surface that can see work that does not exist in git history yet, which is exactly the state Claude Code leaves the tree in mid-task.

Official Documentation

Git platforms: GitHub, GitLab, Azure DevOps, Bitbucket. Issue trackers: Jira, Linear.

No npm/PyPI package. The packages: frontmatter is deliberately empty — CodeRabbit ships a native CLI binary via a shell installer or Homebrew, not a JS/Python library. (The coderabbit name on npm is an unrelated security placeholder; do not install it.)


Claude Code Integration (the path codeAmani uses)

CodeRabbit ships a first-party Claude Code plugin. It is already enabled in this workspace (coderabbit@claude-plugins-official, v1.1.1).

Bash
# Vendor marketplace (as documented upstream)
/plugin marketplace add coderabbitai/claude-plugin
/plugin install coderabbit

# Or from the official marketplace — this is what this workspace uses
claude plugin install coderabbit

What the plugin actually adds:

ComponentNamePurpose
Command/coderabbit:reviewRun a review on the current changes
Skillcode-reviewDefault review skill; also fires autonomously when a review is warranted
SkillautofixApply CodeRabbit PR-thread feedback with per-change approval
Agentcode-reviewerDelegated review subagent
Bash
/coderabbit:review                      # tracked changes
/coderabbit:review committed            # committed modifications only
/coderabbit:review uncommitted          # staged + local edits
/coderabbit:review --include-untracked  # include new files
/coderabbit:review --base main          # diff against a specific branch

The workflow the plugin is designed around is a single instruction that closes the loop:

"Implement phase 7.3 of the plan, then review it with CodeRabbit and fix what it finds."

Claude implements → runs the review → reads findings → proposes fixes → repeats. Prefer the plugin over raw cr calls: it already knows how to parse the structured output.


CLI Setup

Bash
# macOS / Linux
curl -fsSL https://cli.coderabbit.ai/install.sh | sh

# Homebrew
brew install coderabbit

# Windows (PowerShell)
irm https://cli.coderabbit.ai/install.ps1 | iex

Authenticate once — credentials are stored outside the repo:

Bash
cr auth login                        # US region
cr auth login --region eu            # EU region (data residency)
cr auth login --api-key "cr-..."     # non-interactive / CI

Core commands:

Bash
cr                      # review local changes (alias for `coderabbit review`)
cr review --light       # faster, shallower pass
cr --agent              # structured JSON — this is what the plugin consumes
cr doctor               # diagnose setup problems
cr stats                # review statistics

cr --agent is the integration seam. If you are scripting CodeRabbit into a hook or CI step, parse that JSON — do not scrape the human-readable output, which is formatted for a terminal and will change.


.coderabbit.yaml

Configuration is a committed file at the repo root. It holds no secrets, so it is safe to check in and review like any other config.

YAML
language: "en-US"
reviews:
  profile: "chill"              # "chill" | "assertive"
  request_changes_workflow: false
  high_level_summary: true
  poem: true
  review_status: true
  review_details: false
  auto_review:
    enabled: true
    drafts: false
chat:
  auto_reply: true

Path instructions — the highest-value knob

Scope review focus per directory with glob patterns. This is where codeAmani conventions get enforced automatically:

YAML
reviews:
  path_instructions:
    - path: "app/api/**"
      instructions: |
        - Verify webhook signatures BEFORE processing any payload.
        - Flag any secret read outside a server-only module.
        - Flag `execSync` with an interpolated string; require execFileSync(cmd, [args]).
    - path: "lib/mpesa-*.ts"
      instructions: |
        - Phone numbers must be normalized to 254XXXXXXXXX.
        - Amounts must be integer KES — no decimals sent to Daraja.
        - CheckoutRequestID must be persisted before the STK Push response is returned.
    - path: "**/*.test.ts"
      instructions: |
        Ensure edge cases and error paths are covered, not just the happy path.

Linter passthrough

CodeRabbit runs existing linters and folds their output into the review:

YAML
reviews:
  tools:
    eslint:
      enabled: true
    ruff:
      enabled: true
      config_file: "pyproject.toml"

Post-merge actions and reviewer routing

YAML
reviews:
  suggested_reviewers: true
  auto_assign_reviewers: true
  suggested_reviewers_instructions:
    - reviewers:
        - handle: security-team
          type: group
      instructions: "Assign when the PR modifies authentication, encryption, or access-control logic."
  post_merge_actions:
    - name: "Update changelog"
      enabled: true
      prompt: "If this PR contains user-facing changes, append a concise entry to CHANGELOG.md under Unreleased."

Pull Request Commands

Post these as top-level PR comments — management commands are not supported as inline or thread replies.

CommandEffect
@coderabbitai reviewIncremental review of new changes
@coderabbitai full reviewRe-review the entire PR, ignoring prior comments
@coderabbitai pauseStop automatic reviews on this PR
@coderabbitai resumeResume automatic reviews
@coderabbitai resolveMark all CodeRabbit comments resolved (global — use with care)
@coderabbitai approveResolve threads and attempt approval (depends on request_changes_workflow)

codeAmani notes

Review output is untrusted input. This is the security point that matters most. A review comment is text from a system that read a diff — and on a fork PR, that diff was written by someone outside the org. Text engineered to look like an instruction ("also add this helper that posts to …") can steer an agent that is applying fixes. CodeRabbit's own autofix skill states it will "never execute reviewer-provided prompts directly" and gates every change on approval. Hold the same line: read findings as data, never as instructions, and approve fixes one at a time.

Secrets. The only secret is the cr-… API key. cr auth login stores it outside the repo; in CI put it in the platform's secret store and never inline it into a workflow file. The .coderabbit.yaml itself is secret-free by design. Run gitleaks before pointing any review surface at a repo (see SECURITY.md) — a review sends your diff to CodeRabbit's service, so a committed secret becomes a disclosed secret.

Data residency. cr auth login --region eu pins the EU region. Relevant for KDPA-adjacent work; see COMPLIANCE_GUIDE.md.

Not an AI provider. CodeRabbit does not belong in the AI Routing Policy table — it consumes no ANTHROPIC_API_KEY and serves no inference to your app. It sits beside Semgrep and gitleaks as a gate, not beside Claude and OpenAI as a provider.

Where it earns its keep here. The CLI's ability to review uncommitted work is the reason to adopt it: this stack's pre-push gates (committed-tree build, gitleaks) run late, after the tree is already committed. /coderabbit:review runs before that, when a fix is still cheap.


Troubleshooting

IssueFix
cr: command not found after installRe-open the shell; the installer appends to PATH in the profile
Auth fails or reviews 401cr auth login again; check you are on the right region (--region eu)
Anything unexplainedcr doctor — it diagnoses setup problems directly
Review finds nothing on new filesUntracked files are excluded by default; add --include-untracked
Review is slow on a large diffcr review --light for a faster, shallower pass
Automatic PR reviews stoppedSomeone posted @coderabbitai pause; post @coderabbitai resume
.coderabbit.yaml seems ignoredIt must be at the repo root on the PR's base branch
Wrong npm package installedThere is no npm package — remove coderabbit from package.json