Shippie

An extendable code review agent that reads your diff, explores the codebase with real developer tools and leaves focused PR comments

CLI

High risk

We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.

Why this level

  • Requires a model provider key as a secret and writes comments directly into the pull request
All reasons and checks

mattzcarey/shippie

Install

In your terminal, with SkillFoxx CLI

npx skillfoxx add cli/shippie

Detects the agents on your machine, checks the risk and pins the version.

Other ways to install

Install the tool

npm install -g shippie

You will need: Node.js

Checked against the repository on Sep 25, 2026, commit 23e91d0.

Text for your agent

For a local run: npx shippie review (checks staged changes, git diff --cached). For CI, run npx shippie init to scaffold the GitHub Actions workflow, and add your model provider key as a repository secret.

Other ways from the author
npx shippie review

Local run: reviews staged changes (git diff --cached), results are saved to .shippie/review/.

This is third-party code. Review the repository files before installing.

What it does

Shippie runs an agent loop over a pull request diff: it reads the changes, explores the rest of the codebase and looks for what a human reviewer typically catches, such as exposed secrets, inefficient code or unhandled edge cases. It runs as a GitHub Action, locally via npx to review staged changes, or on demand through a /shippie review comment on a PR. Shippie can itself act as an MCP client and reach external tools like a browser or a knowledge base through remote MCP servers listed in its run configuration.

Who it is for. For development teams who want an automated first-pass code review in CI before a PR reaches a human.

Good fit when

  • You want automated code review on every pull request in CI
  • You want to run a targeted check locally against staged changes
  • You need to give the reviewer agent access to external tools via MCP, such as a browser for debugging

Not a fit when

  • You need an MCP server with a stdio transport: Shippie only supports remote MCP servers over HTTP or SSE
  • You have no key for your chosen model provider and won't get one

Example request

Run Shippie over my staged changes and show me what it found

Limitations

Requires a model provider key: Anthropic, OpenAI, OpenRouter or Cloudflare Workers AI. MCP servers must be remote over HTTP or SSE; local command/args-based servers are no longer supported. The GitHub Action needs a full checkout (fetch-depth 0) and pull-request write permissions.

How to disable. Remove the mattzcarey/shippie step from the GitHub Actions workflow, and remove the shippie package from dependencies if it was installed locally.

Security check

  • Requires a model provider key as a secret and writes comments directly into the pull request

README in short

The README describes Shippie as an extendable code review agent built on the flue and pi frameworks: it reads the diff, uses flue's built-in developer tools instead of a hand-rolled tool registry, and can connect as an MCP client to remote servers. It runs as a GitHub Action, locally via npx shippie review for staged changes, or on a PR comment command. It supports Node, Cloudflare Workers, GitHub Actions and GitLab CI, with model providers configured via environment variables.

FAQ

Can review be triggered by a comment?

Yes, a /shippie review comment on a pull request triggers a run through either a GitHub Actions workflow or a deployed webhook.

Which model providers are supported?

Anthropic, OpenAI, OpenRouter and Cloudflare Workers AI; the key is passed as an environment variable or an Action secret.

Editors’ pick

A CLI for testing and red teaming LLM applications: compares models, runs automated CI checks and finds vulnerabilities

CLIMedium risk25.5KRepository stars

Playwright CLI

playwright-cli

Editors’ pick

Microsoft's official Playwright CLI with an agent skill: drive a browser through short commands without heavy MCP schemas

CLIMedium riskNo VPN needed13.6KRepository stars
Editors’ pick

The official MCP server debugger: web UI, automation CLI and terminal UI in one package

CLIMedium riskNo VPN needed11KRepository stars
Official

SonarSource's official MCP server: quality and security issues, quality gates and code analysis from SonarQube Server and Cloud

MCP serverMedium risk655Repository stars
Foxx AIShippie

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.