Review Assist blog

Better reviews for AI-written code

Architecture, practice, and field notes for teams reviewing code at agent speed.

Articles

ArticleHow Review Assist’s architecture catches bugs before code review3 Oct 2026

A two-agent, evidence-gated approach to reviewing AI-generated code while the implementation can still change.

Release notes

v1.0.5Start both roles at once, and stop the interview deadlocking21 Sep 2026

The distillation spent most of its time with one role waiting on the other. Both roles now start together, the two-batch cap is enforced, and a waiting reviewer is told when to stop.

v1.0.4Finish a release that half-shipped8 Sep 2026

1.0.3 reached npm and stopped there, missing from the MCP registry and the releases page with nothing able to finish it. Also: the cache purge that failed every deploy.

v1.0.3A repository can teach the reviewer its own questions8 Sep 2026

A .reviewer/ folder holds what only your repository knows to ask. Published to npm, but not to the MCP registry or the releases page; 1.0.4 fixed that.

v1.0.2The viewer’s columns stop drifting29 Aug 2026

On wide displays the two-column layouts sat centred in a gutter that grew with the window, and at some widths the diff got less room than it had in one column.

v1.0.1Shorter documents, and an interview that survives a commit25 Aug 2026

Intent Documents are now written in points instead of paragraphs. Underneath: three ways the interview silently lost its answers.

v1.0.0Nothing large enough to matter can go missing13 Aug 2026

A paged session spine, an interview the server can attest from both sides, and the schema fix that made every submission fail.

v0.3.1No response grows with the size of the change6 Aug 2026

The flow died on exactly the changes big enough to deserve a document. Paged diffs, hunk-id anchors, a run handle that survives a restart.

v0.2.11Role definitions install at the handshake29 Jul 2026

Written during a tool call, they could not be dispatched until the next session — so agents simulated the split without the allowlist that enforces it.

v0.2.10The server installs the roles, at user scope29 Jul 2026

The guide told agents to run a CLI that could not detect their client, so they wrote subagent files into whatever repository they happened to be in.

v0.2.9Check the invariants; name the silent install failure29 Jul 2026

Two releases had broken on cross-file invariants no generator owns. Separately: why npx-based servers show as not connected in GUI editors, with no error.

v0.2.8Publishing to the MCP registry29 Jul 2026

server.json had drifted two versions behind npm, and the registry could not verify the package was ours.

v0.2.7Say what the thing actually is29 Jul 2026

The npm README listed five tools where the server registers ten, and never mentioned that half the product is a GitHub App. The privacy claim was overstated too.

v0.2.6Pin the toolchain29 Jul 2026

npm i -g npm@latest made every release depend on whatever npm shipped that hour.

v0.2.5Push an annotated tag29 Jul 2026

git tag creates a lightweight tag; git push --follow-tags only pushes annotated ones.

v0.2.4Commit and tag from the repository root29 Jul 2026

npm version inside a workspace package bumps package.json and silently does nothing in git.

v0.2.3One version, derived everywhere29 Jul 2026

Three files carried a version and the release bumped one, so 0.2.2 shipped a server that reported itself as 0.2.1.

v0.2.2Trusted publishing, and the bundle the README promised29 Jul 2026

The publish workflow depended on a secret that was never set, and never attached the .mcpb the README links to.

v0.2.1First published release29 Jul 2026

The format, the validator, the MCP server and the guided-review app — and the decision to retire the GitHub Action.