Shippie
An extendable code review agent that reads your diff, explores the codebase with real developer tools and leaves focused PR comments
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- Requires a model provider key as a secret and writes comments directly into the pull request
Install
In your terminal, with SkillFoxx CLI
npx skillfoxx add cli/shippieDetects the agents on your machine, checks the risk and pins the version.
Other ways to install
Install the tool
npm install -g shippieFor a local run: npx shippie review (checks staged changes, git diff --cached). For CI, run npx shippie init to scaffold the GitHub Actions workflow, and add your model provider key as a repository secret.
Other ways from the author
npx shippie reviewLocal run: reviews staged changes (git diff --cached), results are saved to .shippie/review/.
This is third-party code. Review the repository files before installing.
What it does
Shippie runs an agent loop over a pull request diff: it reads the changes, explores the rest of the codebase and looks for what a human reviewer typically catches, such as exposed secrets, inefficient code or unhandled edge cases. It runs as a GitHub Action, locally via npx to review staged changes, or on demand through a /shippie review comment on a PR. Shippie can itself act as an MCP client and reach external tools like a browser or a knowledge base through remote MCP servers listed in its run configuration.
Who it is for. For development teams who want an automated first-pass code review in CI before a PR reaches a human.
Good fit when
- You want automated code review on every pull request in CI
- You want to run a targeted check locally against staged changes
- You need to give the reviewer agent access to external tools via MCP, such as a browser for debugging
Not a fit when
- You need an MCP server with a stdio transport: Shippie only supports remote MCP servers over HTTP or SSE
- You have no key for your chosen model provider and won't get one
Example request
Run Shippie over my staged changes and show me what it foundLimitations
Requires a model provider key: Anthropic, OpenAI, OpenRouter or Cloudflare Workers AI. MCP servers must be remote over HTTP or SSE; local command/args-based servers are no longer supported. The GitHub Action needs a full checkout (fetch-depth 0) and pull-request write permissions.
How to disable. Remove the mattzcarey/shippie step from the GitHub Actions workflow, and remove the shippie package from dependencies if it was installed locally.
Security check
- Requires a model provider key as a secret and writes comments directly into the pull request
README in short
The README describes Shippie as an extendable code review agent built on the flue and pi frameworks: it reads the diff, uses flue's built-in developer tools instead of a hand-rolled tool registry, and can connect as an MCP client to remote servers. It runs as a GitHub Action, locally via npx shippie review for staged changes, or on a PR comment command. It supports Node, Cloudflare Workers, GitHub Actions and GitLab CI, with model providers configured via environment variables.
FAQ
Can review be triggered by a comment?
Yes, a /shippie review comment on a pull request triggers a run through either a GitHub Actions workflow or a deployed webhook.
Which model providers are supported?
Anthropic, OpenAI, OpenRouter and Cloudflare Workers AI; the key is passed as an environment variable or an Action secret.
Related
A CLI for testing and red teaming LLM applications: compares models, runs automated CI checks and finds vulnerabilities
Playwright CLI
playwright-cli
Microsoft's official Playwright CLI with an agent skill: drive a browser through short commands without heavy MCP schemas
The official MCP server debugger: web UI, automation CLI and terminal UI in one package
SonarSource's official MCP server: quality and security issues, quality gates and code analysis from SonarQube Server and Cloud