AiCodeReview.Analyzer 1.1.0

There is a newer version of this package available.
See the version list below for details.
dotnet add package AiCodeReview.Analyzer --version 1.1.0
                    
NuGet\Install-Package AiCodeReview.Analyzer -Version 1.1.0
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="AiCodeReview.Analyzer" Version="1.1.0">
  <PrivateAssets>all</PrivateAssets>
  <IncludeAssets>runtime; build; native; contentfiles; analyzers</IncludeAssets>
</PackageReference>
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="AiCodeReview.Analyzer" Version="1.1.0" />
                    
Directory.Packages.props
<PackageReference Include="AiCodeReview.Analyzer">
  <PrivateAssets>all</PrivateAssets>
  <IncludeAssets>runtime; build; native; contentfiles; analyzers</IncludeAssets>
</PackageReference>
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add AiCodeReview.Analyzer --version 1.1.0
                    
#r "nuget: AiCodeReview.Analyzer, 1.1.0"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package AiCodeReview.Analyzer@1.1.0
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=AiCodeReview.Analyzer&version=1.1.0
                    
Install as a Cake Addin
#tool nuget:?package=AiCodeReview.Analyzer&version=1.1.0
                    
Install as a Cake Tool

AiCodeReview.Analyzer

Automatic AI-powered code review on every build — surfaced as compiler warnings directly inside Visual Studio.

NuGet NuGet Downloads


What is it?

AiCodeReview.Analyzer is a Roslyn diagnostic analyzer that hooks into the C# compiler pipeline. Every time you build, it reviews your code using AI and surfaces actionable feedback inline in Visual Studio as compiler warnings — no extra tools, no copy-paste, no browser.

Not a SonarQube replacement. It is a powerful shift-left complement — it catches bugs, vulnerabilities, and code smells before commit so fewer issues reach your Sonar quality gate.


Install

dotnet add package AiCodeReview.Analyzer

Or search AiCodeReview.Analyzer in Visual Studio - NuGet Package Manager and click Install.


Setup

Set your AI API key as an environment variable before building:

PowerShell (current session)

$env:AI_CODE_REVIEW_KEY = "your-api-key"

System-wide (recommended for team use)

[System.Environment]::SetEnvironmentVariable("AI_CODE_REVIEW_KEY", "your-api-key", "User")

GitHub Actions / CI

env:
  AI_CODE_REVIEW_KEY: ${{ secrets.AI_CODE_REVIEW_KEY }}

If AI_CODE_REVIEW_KEY is not set the analyzer silently skips — your build is never broken.


Optional — use a custom endpoint

To point the analyzer at a different AI backend, set:

$env:AI_CODE_REVIEW_URL = "your-chat-completions-endpoint"

Works with Azure OpenAI, Ollama, or any OpenAI-compatible API.


Diagnostic IDs

ID Severity SonarQube Equivalent Catches
AICR001 Error Bugs Null refs, logic errors, incorrect behaviour — S2259, S2583
AICR002 Error Vulnerabilities SQL injection, hardcoded credentials, weak crypto — S3649, S2068, S4790
AICR003 Warning Security Hotspots CSRF, XSS, path traversal — S4502, S5042
AICR004 Warning Performance Bad loops, LINQ misuse, multiple enumeration — S3267, S2971
AICR005 Warning Code Smells Naming, duplication, dead code — S1481, S1172, S138
AICR006 Warning Cognitive Complexity Methods exceeding complexity threshold — S3776
AICR007 Error Null Safety Null dereference, uninitialized access — S2259, S3655

Real example output

Class1.cs(122): error   AICR002: SQL injection via string concatenation in query (S3649)
Class1.cs(154): error   AICR002: Weak cryptographic algorithm MD5 - use SHA256 or Argon2 (S4790)
Class1.cs(71):  error   AICR001: Infinite recursion - no base case - stack overflow risk (S2259)
Class1.cs(58):  error   AICR001: Condition always true - role != Admin || role != User (S2583)
Class1.cs(26):  warning AICR006: Cognitive complexity exceeds threshold (S3776)

Developer writes code
        |
        v
AiCodeReview.Analyzer  —  catches issues BEFORE commit, instant feedback in VS
        |
        v
Git commit / PR
        |
        v
SonarQube CI scan      —  enforces rules, gates, metrics, compliance (authoritative)

Auto-apply to every project in a solution

Drop a Directory.Build.props at your repo root — every project gets reviewed with no .csproj changes needed:

<Project>
  <ItemGroup Condition="'$(MSBuildProjectName)' != 'AiCodeReview.Analyzer'">
    <PackageReference Include="AiCodeReview.Analyzer" Version="1.0.9">
      <IncludeAssets>runtime; build; native; contentfiles; analyzers; buildtransitive</IncludeAssets>
      <PrivateAssets>all</PrivateAssets>
    </PackageReference>
  </ItemGroup>
</Project>

Control severity via .editorconfig

[*.cs]
dotnet_diagnostic.AICR001.severity = error
dotnet_diagnostic.AICR002.severity = error
dotnet_diagnostic.AICR003.severity = warning
dotnet_diagnostic.AICR004.severity = warning
dotnet_diagnostic.AICR005.severity = suggestion
dotnet_diagnostic.AICR006.severity = warning
dotnet_diagnostic.AICR007.severity = error

Suppress for a specific block:

#pragma warning disable AICR001
public void MyMethod() { }
#pragma warning restore AICR001

Requirements

Visual Studio 2019 or later
.NET Any (.NET Standard 2.0 compatible)
AI API key Required (set via AI_CODE_REVIEW_KEY environment variable)

License

MIT (c) ravikalluri

There are no supported framework assets in this package.

Learn more about Target Frameworks and .NET Standard.

This package has no dependencies.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
1.1.4 149 5/12/2026
1.1.3 121 5/12/2026
1.1.2 110 5/12/2026
1.1.1 111 5/12/2026
1.1.0 115 5/12/2026
1.0.9 110 5/12/2026
1.0.8 113 5/12/2026
1.0.6 121 5/12/2026
1.0.5 110 5/12/2026
1.0.4 118 5/12/2026
1.0.3 109 5/12/2026
1.0.2 105 5/12/2026
1.0.0 136 5/12/2026