AI code review means a second model reads the code an agent wrote and reports problems. The trap with agents is speed: an agent changes dozens of files in one turn, and reading all of it line by line gives back the time the agent saved you. A review step closes that gap; the agent’s output passes a second pair of eyes before you look.
This post covers how to have agent output reviewed, how to weigh the findings and how to keep the review loop under control.
Why review agent output separately?
The agent that wrote the code is blind to its own assumptions. When an agent marks a change “done”, it often misses:
- Missing rollback or cleanup on error paths
- Edge cases: empty input, concurrent requests, timeouts
- Security: reusable tokens, unvalidated input
- Unused imports, dead code, inconsistent naming
A second model reading the same code with a fresh context, looking only at the diff, notices these more easily.
What good AI code review looks at
Findings only help when you can act on them. A good finding has:
| Part | Example |
|---|---|
| Severity | High, medium, low |
| Location | src/auth/session.ts:88 |
| Problem | “A new token is issued before the old one is revoked.” |
| Why it matters | “Token reuse isn’t detected.” |
Severity sets priority. Location takes you straight to the line. Vague “improve the code” comments are no use at all.
When to review
Three approaches:
- Automatically after every turn. Review starts as soon as the agent finishes its turn, so problems are caught while the agent still has the context.
- Before merging. Review the whole diff before the branch goes into the main branch.
- On demand. Review a commit or the working tree you’re unsure about.
With agents, the first saves the most time, because problems surface before they spread to the next turn.
Automatic code review in AgentVera
AgentVera’s code review is turned on in the project settings and shows up in the Reviews tab of the right panel:
- Turn on automatic review in the project settings and pick a Claude model.
- Choose what gets reviewed: the commits from the turn, or all changes.
- Choose whether findings go back to the agent.
- When the agent finishes its turn, the review runs; findings are listed with severity and file:line links.
You can also review the working tree, staged changes or a single commit by hand.
Bound the feedback loop
Sending findings back to the agent automatically is tempting, but an endless loop is risky: the agent fixes one issue and introduces another, the review finds it, and on it goes. That’s why AgentVera limits feedback to at most two rounds in a row. After that, the call is yours.
How to weigh findings
You don’t have to accept every finding. A practical order:
- High: security and data-loss risks. Fix before merging.
- Medium: error paths, missing tests. Usually cheap to fix in the same turn.
- Low: style, unused imports. Clean up in bulk or with automated tools.
Don’t hesitate to reject false positives. The reviewing model can be wrong too; you know the context best.
Combine review with other safety nets
Review alone isn’t enough. It’s stronger together with:
- Tests: review catches logic errors, tests catch behavior errors.
- Turns: if a review shows a turn went the wrong way, undo it with turns.
- Notifications: get told on Telegram when an important finding appears.
- Flows: add a review or test agent after the builder agent.
A sample review report
In one turn, the agent added a refresh token flow and made three commits. When the turn ends, the review produces:
| Severity | Finding | Location |
|---|---|---|
| High | Refresh token reuse isn’t detected; a new token is issued before the old one is revoked. | src/auth/session.ts:88 |
| Medium | The database transaction isn’t rolled back on the error path. | src/auth/store.ts:41 |
| Low | Unused import. | src/auth/index.ts:3 |
What do you do with this?
- Send the high finding to the agent. It’s a security issue and the agent still has the context, so the fix is cheap.
- Add the medium finding to the same turn. Error-path behavior needs a test; ask the agent to write one.
- Batch the low finding. A linter or the next cleanup pass will handle it.
Once the agent fixes things, the review runs again. If findings are still open after the second round, the automatic loop stops and the decision is yours.
Picking a model and scope for review
Review has a cost too. Reviewing every turn with the strongest model can get expensive. A practical approach:
- For everyday turns, pick a faster, cheaper Claude model.
- Before merging, consider reviewing the whole diff by hand with a stronger model.
- Limiting scope to the turn’s commits keeps the reviewed diff small; reviewing all changes also catches uncommitted work.
Feed review back into the agent’s role
If you see the same patterns in findings again and again, move them into the agent’s role. If the review keeps flagging missing error-path tests, add a line like this:
For every new function, write at least one error-path test next to the happy-path test.
Then the same issue stops showing up every turn; the agent prevents it up front. Over time the reports get shorter and the findings that matter stand out.
Reading reviews alongside history helps too. AgentVera’s conversation search runs full-text search across all Claude and Codex conversations, so you can find the session where an issue was discussed before and resume it in a new agent.
Checklist
- Is automatic review on in the project settings?
- Does the review scope (turn commits or all changes) fit your work?
- Were high-severity findings closed before merging?
- Is the feedback loop bounded?
- Were the tests run independently of the review?
Wrapping up
AI code review lets you use agents’ speed without giving up quality. A second model reading the code after every turn catches problems while the agent still has the context, and findings with severity and location tell you where to look first.
In AgentVera you turn review on per project and send findings to the agent in one click. Use it with the merge steps in git worktrees for parallel agents, or start on the free plan.