--light No key, no network, no excuse

local review

The cheapest review is the one before the PR

buddy review reads your working tree — staged changes included — and tells you what a reviewer would say. No pull request to open, no CI queue to wait for, and with --light, no API key at all.

$ buddy review --staged --light --fail-on major

             __
    (\,------'()'--o    analyzers only
     (_    ___    /~"   no key, no network
      (_)_)  (_)_)

  secrets      scanning 6 staged files
  actionlint   .github/workflows/ci.yml
  shellcheck   scripts/release.sh
  yaml/json    3 files

  scripts/release.sh:12  major  security
    AWS key literal in the deploy step.

  1 major finding — commit blocked.
$ echo $?
1
📝

Reads what you are about to commit

The default reviews the working tree against HEAD with staged changes included — a pre-commit review that ignored what you just staged would miss the very lines you are committing.

🎯

Three scopes

No flag reviews the working tree, --staged reviews the index only, --branch reviews this branch against its base.

🦴

Works offline

--light skips the model entirely and runs secret scanning, workflow auditing, YAML and JSON validation, and whatever linters the machine has installed — actionlint, shellcheck, hadolint, markdownlint. Fast enough for a hook, and it works on a plane.

🚧

Exit codes, not vibes

--fail-on exits non-zero when something at or above that severity is found. That is what turns a suggestion into a gate.

🩹

Applies its own suggestions

--fix confirms each suggestion; --fix --yes applies them all. Fixes land bottom-up per file, and a suggestion whose line no longer matches is skipped rather than written over an unrelated line.

🔌

Pipes cleanly

json, github annotations, or agent. Every format except pretty owns stdout completely, so no log line lands in the middle of your JSON.

The three commands worth aliasing

buddy review                              # working tree, staged included
buddy review --staged --light --fail-on major   # a pre-commit hook
buddy review --branch --base main         # everything on this branch

No key required

--light is the flag that makes local review universal. It runs the analyzers Buddy ships with and nothing else:

AnalyzerWhat it catches
Secret scanningKeys, tokens and credentials about to be committed
Workflow auditBash injection, excessive permissions, unpinned actions, missing timeouts
actionlintGitHub Actions workflow errors
shellcheckShell script bugs
hadolintDockerfile problems
markdownlintDocumentation lint
Syntax / YAML / JSONFiles that do not parse

Missing analyzer binaries are a warning, not a failure — Buddy runs the ones the machine has. buddy doctor reports which are installed and the command that installs the rest.

In a pre-commit hook

# .git/hooks/pre-commit
#!/bin/sh
buddy review --staged --light --fail-on major

No key, no network, no per-seat cost, and it runs in the seconds you would otherwise spend waiting for CI to tell you the same thing.

Handing findings to a coding agent

buddy review --format agent | claude

--format agent emits an instruction rather than a report. It tells the agent to change only what each finding asks for, and explicitly gives it permission to disagree and leave the code alone — an agent that mechanically applies a wrong finding is worse than one that pushes back.

Diagnosing the setup

buddy doctor

Reports credentials, git state, configuration validity and which analyzer tools are installed, and every problem it finds comes with the command or setting that fixes it. Missing credentials and missing binaries are warnings; doctor exits non-zero only when something is genuinely broken.

AI code review · Workflow security · Local review CLI reference · Working with AI coding agents