AiCodeReview.Analyzer
1.0.8
See the version list below for details.
dotnet add package AiCodeReview.Analyzer --version 1.0.8
NuGet\Install-Package AiCodeReview.Analyzer -Version 1.0.8
<PackageReference Include="AiCodeReview.Analyzer" Version="1.0.8"> <PrivateAssets>all</PrivateAssets> <IncludeAssets>runtime; build; native; contentfiles; analyzers</IncludeAssets> </PackageReference>
<PackageVersion Include="AiCodeReview.Analyzer" Version="1.0.8" />
<PackageReference Include="AiCodeReview.Analyzer"> <PrivateAssets>all</PrivateAssets> <IncludeAssets>runtime; build; native; contentfiles; analyzers</IncludeAssets> </PackageReference>
paket add AiCodeReview.Analyzer --version 1.0.8
#r "nuget: AiCodeReview.Analyzer, 1.0.8"
#:package AiCodeReview.Analyzer@1.0.8
#addin nuget:?package=AiCodeReview.Analyzer&version=1.0.8
#tool nuget:?package=AiCodeReview.Analyzer&version=1.0.8
AiCodeReview.Analyzer
Automatic AI-powered code review on every build — surfaced as compiler warnings directly inside Visual Studio.
What is it?
AiCodeReview.Analyzer is a Roslyn diagnostic analyzer that hooks into the C# compiler pipeline.
Every time you build, it reviews your code using AI and surfaces actionable feedback inline in Visual Studio — no extra tools, no copy-paste, no browser.
Not a SonarQube replacement. It is a powerful shift-left complement — it catches bugs, vulnerabilities, and code smells before commit so fewer issues reach your Sonar quality gate. SonarQube still wins on metrics, quality gates, cross-file analysis, and 500+ deterministic rules.
Install
dotnet add package AiCodeReview.Analyzer
Or search AiCodeReview.Analyzer in Visual Studio - NuGet Package Manager and click Install.
That is it. Build your project and AI warnings appear automatically. Zero configuration required.
Diagnostic IDs
| ID | Severity | SonarQube Equivalent | Catches |
|---|---|---|---|
| AICR001 | Error | Bugs | Null refs, logic errors, incorrect behaviour — S2259, S2583 |
| AICR002 | Error | Vulnerabilities | SQL injection, hardcoded credentials, weak crypto — S3649, S2068, S4790 |
| AICR003 | Warning | Security Hotspots | CSRF, XSS, path traversal — S4502, S5042 |
| AICR004 | Warning | Performance | Bad loops, LINQ misuse, multiple enumeration — S3267, S2971 |
| AICR005 | Warning | Code Smells | Naming, duplication, dead code — S1481, S1172, S138 |
| AICR006 | Warning | Cognitive Complexity | Methods exceeding complexity threshold — S3776 |
| AICR007 | Error | Null Safety | Null dereference, uninitialized access — S2259, S3655 |
How it works
You build
|
v
Roslyn runs analyzer on every method / constructor / property / class / file
|
v
Code is reviewed by AI — MD5 cache skips unchanged code for fast builds
|
v
AICR001-AICR007 warnings appear inline in Visual Studio + Error List + CI logs
Real example output
Class1.cs(122): error AICR002: SQL injection via string concatenation in query (S3649)
Class1.cs(154): error AICR002: Weak cryptographic algorithm MD5 - use SHA256 or Argon2 (S4790)
Class1.cs(71): error AICR001: Infinite recursion - no base case - stack overflow risk (S2259)
Class1.cs(58): error AICR001: Condition always true - role != Admin || role != User (S2583)
Class1.cs(26): warning AICR006: Cognitive complexity exceeds threshold (S3776)
Recommended team setup
Developer writes code
|
v
AiCodeReview.Analyzer — catches issues BEFORE commit, instant feedback in VS
|
v
Git commit / PR
|
v
SonarQube CI scan — enforces rules, gates, metrics, compliance (authoritative)
Auto-apply to every project in a solution
Drop a Directory.Build.props at your repo root — every project gets reviewed with no .csproj changes needed:
<Project>
<ItemGroup Condition="'$(MSBuildProjectName)' != 'AiCodeReview.Analyzer'">
<PackageReference Include="AiCodeReview.Analyzer" Version="1.0.8">
<IncludeAssets>runtime; build; native; contentfiles; analyzers; buildtransitive</IncludeAssets>
<PrivateAssets>all</PrivateAssets>
</PackageReference>
</ItemGroup>
</Project>
Control severity via .editorconfig
[*.cs]
dotnet_diagnostic.AICR001.severity = error
dotnet_diagnostic.AICR002.severity = error
dotnet_diagnostic.AICR003.severity = warning
dotnet_diagnostic.AICR004.severity = warning
dotnet_diagnostic.AICR005.severity = suggestion
dotnet_diagnostic.AICR006.severity = warning
dotnet_diagnostic.AICR007.severity = error
Suppress for a specific block:
#pragma warning disable AICR001
public void MyMethod() { }
#pragma warning restore AICR001
Requirements
| Visual Studio | 2019 or later |
| .NET | Any (.NET Standard 2.0 compatible) |
| Internet | Required at build time |
License
MIT (c) ravikalluri
Learn more about Target Frameworks and .NET Standard.
This package has no dependencies.
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.