AiCodeReview.Analyzer
1.1.0
See the version list below for details.
dotnet add package AiCodeReview.Analyzer --version 1.1.0
NuGet\Install-Package AiCodeReview.Analyzer -Version 1.1.0
<PackageReference Include="AiCodeReview.Analyzer" Version="1.1.0"> <PrivateAssets>all</PrivateAssets> <IncludeAssets>runtime; build; native; contentfiles; analyzers</IncludeAssets> </PackageReference>
<PackageVersion Include="AiCodeReview.Analyzer" Version="1.1.0" />
<PackageReference Include="AiCodeReview.Analyzer"> <PrivateAssets>all</PrivateAssets> <IncludeAssets>runtime; build; native; contentfiles; analyzers</IncludeAssets> </PackageReference>
paket add AiCodeReview.Analyzer --version 1.1.0
#r "nuget: AiCodeReview.Analyzer, 1.1.0"
#:package AiCodeReview.Analyzer@1.1.0
#addin nuget:?package=AiCodeReview.Analyzer&version=1.1.0
#tool nuget:?package=AiCodeReview.Analyzer&version=1.1.0
AiCodeReview.Analyzer
Automatic AI-powered code review on every build — surfaced as compiler warnings directly inside Visual Studio.
What is it?
AiCodeReview.Analyzer is a Roslyn diagnostic analyzer that hooks into the C# compiler pipeline.
Every time you build, it reviews your code using AI and surfaces actionable feedback
inline in Visual Studio as compiler warnings — no extra tools, no copy-paste, no browser.
Not a SonarQube replacement. It is a powerful shift-left complement — it catches bugs, vulnerabilities, and code smells before commit so fewer issues reach your Sonar quality gate.
Install
dotnet add package AiCodeReview.Analyzer
Or search AiCodeReview.Analyzer in Visual Studio - NuGet Package Manager and click Install.
Setup
Set your AI API key as an environment variable before building:
PowerShell (current session)
$env:AI_CODE_REVIEW_KEY = "your-api-key"
System-wide (recommended for team use)
[System.Environment]::SetEnvironmentVariable("AI_CODE_REVIEW_KEY", "your-api-key", "User")
GitHub Actions / CI
env:
AI_CODE_REVIEW_KEY: ${{ secrets.AI_CODE_REVIEW_KEY }}
If
AI_CODE_REVIEW_KEYis not set the analyzer silently skips — your build is never broken.
Optional — use a custom endpoint
To point the analyzer at a different AI backend, set:
$env:AI_CODE_REVIEW_URL = "your-chat-completions-endpoint"
Works with Azure OpenAI, Ollama, or any OpenAI-compatible API.
Diagnostic IDs
| ID | Severity | SonarQube Equivalent | Catches |
|---|---|---|---|
| AICR001 | Error | Bugs | Null refs, logic errors, incorrect behaviour — S2259, S2583 |
| AICR002 | Error | Vulnerabilities | SQL injection, hardcoded credentials, weak crypto — S3649, S2068, S4790 |
| AICR003 | Warning | Security Hotspots | CSRF, XSS, path traversal — S4502, S5042 |
| AICR004 | Warning | Performance | Bad loops, LINQ misuse, multiple enumeration — S3267, S2971 |
| AICR005 | Warning | Code Smells | Naming, duplication, dead code — S1481, S1172, S138 |
| AICR006 | Warning | Cognitive Complexity | Methods exceeding complexity threshold — S3776 |
| AICR007 | Error | Null Safety | Null dereference, uninitialized access — S2259, S3655 |
Real example output
Class1.cs(122): error AICR002: SQL injection via string concatenation in query (S3649)
Class1.cs(154): error AICR002: Weak cryptographic algorithm MD5 - use SHA256 or Argon2 (S4790)
Class1.cs(71): error AICR001: Infinite recursion - no base case - stack overflow risk (S2259)
Class1.cs(58): error AICR001: Condition always true - role != Admin || role != User (S2583)
Class1.cs(26): warning AICR006: Cognitive complexity exceeds threshold (S3776)
Recommended team setup
Developer writes code
|
v
AiCodeReview.Analyzer — catches issues BEFORE commit, instant feedback in VS
|
v
Git commit / PR
|
v
SonarQube CI scan — enforces rules, gates, metrics, compliance (authoritative)
Auto-apply to every project in a solution
Drop a Directory.Build.props at your repo root — every project gets reviewed with no .csproj changes needed:
<Project>
<ItemGroup Condition="'$(MSBuildProjectName)' != 'AiCodeReview.Analyzer'">
<PackageReference Include="AiCodeReview.Analyzer" Version="1.0.9">
<IncludeAssets>runtime; build; native; contentfiles; analyzers; buildtransitive</IncludeAssets>
<PrivateAssets>all</PrivateAssets>
</PackageReference>
</ItemGroup>
</Project>
Control severity via .editorconfig
[*.cs]
dotnet_diagnostic.AICR001.severity = error
dotnet_diagnostic.AICR002.severity = error
dotnet_diagnostic.AICR003.severity = warning
dotnet_diagnostic.AICR004.severity = warning
dotnet_diagnostic.AICR005.severity = suggestion
dotnet_diagnostic.AICR006.severity = warning
dotnet_diagnostic.AICR007.severity = error
Suppress for a specific block:
#pragma warning disable AICR001
public void MyMethod() { }
#pragma warning restore AICR001
Requirements
| Visual Studio | 2019 or later |
| .NET | Any (.NET Standard 2.0 compatible) |
| AI API key | Required (set via AI_CODE_REVIEW_KEY environment variable) |
License
MIT (c) ravikalluri
Learn more about Target Frameworks and .NET Standard.
This package has no dependencies.
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.