Otto Detective · AI code review for GitHub & Azure DevOps

Every pull request, investigated.

Otto Detective reviews each pull request as soon as it opens — tracing the change across your codebase, flagging issues by severity on the lines that changed, and ending with a merge-confidence score your team can act on.

Starts with a free welcome creditNo credit card required Using Azure DevOps? Start here

otto-detectivebot approved these changes

Otto Review — Otto review complete

Details

Tip

Merge confidence: 5/5 — the overspend race is fixed and covered by a test

What lands on the pull request. Example for illustration.

How it works

Install once. Otto reviews from there.

No new dashboard to check and no workflow to change. Otto shows up where your team already reviews code.

  1. 01

    Install Otto Detective

    Add the GitHub App and choose the repositories Otto can review — or connect Azure DevOps with a service principal.

  2. 02

    Open a pull request

    Otto starts reviewing as soon as a PR opens. A status check shows its progress and never blocks a merge.

  3. 03

    Get a verdict

    Otto approves, requests changes, or comments — with findings on the lines that changed and a merge-confidence score.

  4. 04

    Push, reply, re-review

    On GitHub, pushing a fix triggers a fresh review that updates the same summary. Reply in a thread or comment /otto review anytime.

Sample review

One summary. Everything you need to merge.

On GitHub, Otto keeps a single summary on each pull request and updates it after every review — the verdict, the findings, a map of what changed, and how the merge confidence has moved.

Enforce credit balance on spend #184

acme/api

Example

Summary comment · updated after the fix

otto-detectivebotcommented · edited

Otto Summary

Verdict: ✅ Approved

The balance check now runs inside the transaction that deducts credits, so concurrent spends can no longer overdraw an account. A new concurrency test covers the race.

Findings

No new findings.

Change flow diagram

POST /credits/spend calls
spendCredits()
locks, then deducts credit_ledger

Tip

Merge confidence: 5/5 — the overspend race is fixed and covered by a test


Confidence trend (oldest → newest): 2/5 → 5/5

Review history (2 runs)

ReviewedCommitVerdictScoreNew findings
10:42 AM3f9a2c1❌ Changes requested2/51
11:05 AM8b41e07✅ Approved5/50

Inline finding · first review

src/billing/credits.ts

41const account = await accounts.find(id);
42const balance = account.balance;
43if (balance >= cost) return deduct(id, cost);
otto-detectivebot

P1Balance checked outside the transaction

The balance is read before the transaction that deducts credits, so two concurrent requests can both pass this check and overspend the account.

Suggested change

42−const balance = account.balance;
43−if (balance >= cost) return deduct(id, cost);
42+return db.transaction(async (tx) => {
43+ const { balance } = await tx.lock(id);
44+ if (balance < cost) throw new NoCredits();
45+ return tx.deduct(id, cost);
46+});
Apply suggestion

Prompt To Fix With AI

otto-detective Fixed in 8b41e07 — the balance is now read under a row lock inside the deduct transaction.

Illustrative example based on how Otto formats reviews on GitHub. Azure DevOps shows the verdict, findings, and merge-confidence score in its own format.

GitHub

One living summary

A single comment per pull request, updated after every review with the confidence trend and full review history.

GitHub

Change-flow diagram

A map of the components, endpoints, and tables a PR touches, color-coded by what was added, modified, or removed.

Fixes you can apply

One-click GitHub suggestions where the fix is clear, plus a ready-to-paste prompt for your AI coding tool on every finding.

What it checks

Reviewed the way a senior engineer would

Otto reads beyond the diff — following definitions, callers, and tests across the repository — then ranks what it finds by severity and scores how safe the change is to merge.

Correctness

Is the change logically sound, and does it do what the PR says?

Likely bugs

Off-by-one errors, null handling, race conditions, unhandled rejections.

Security

Input validation, authN/authZ, injection vectors, secret leakage.

Performance

N+1 queries, accidental quadratic loops, wasted work in hot paths.

Tests

Is new behavior covered? Are existing tests still accurate?

Style

Does it match your repository's conventions and naming?

Every finding has a severity

So your team knows what blocks a merge and what can wait.

  • P0

    Critical — Data loss, a security breach, an outage, or a broken build.

  • P1

    High impact — A high-impact bug or security issue.

  • P2

    Correctness & tests — Correctness, reliability, or missing-test issues to fix before merge.

  • P3

    Suggestions — Non-blocking nitpicks, style, and maintainability.

Every review ends with a merge-confidence score

Recomputed from the current diff on each review, with the reason in one sentence.

  • 5/5

    Safe to merge — No P0, P1, or P2 findings remain.

  • 4/5

    Safe to merge — Only minor P2 concerns — nothing P0 or P1.

  • 3/5

    Medium risk — P2 issues worth fixing, though none block on their own.

  • 2/5

    Not safe to merge — At least one P1, or several serious P2s.

  • 1/5

    Blocker — A P0 or a high-confidence risk like data loss, a security hole, or a deploy break.

Anchored to the change

Inline findings land on the exact line that changed. Broader concerns go in the summary.

No repeats

Duplicate findings are dropped, and a finding you decline stays declined on that PR.

Moved by evidence

Fix or refute a finding and Otto updates its verdict. Disagreement alone won't earn an approval.

Works where you review

Native to GitHub and Azure DevOps

Otto posts real reviews on your pull requests, so there's nothing new for your team to learn or check.

GitHub

Install the Otto Detective GitHub App on the repositories you choose.

  • Native reviews: approve, request changes, or comment
  • Inline findings with one-click suggested fixes
  • One living summary per PR, with a change-flow diagram
  • An “Otto Review” check that never blocks a merge — or make it required so merges wait for Otto
  • Automatic re-review when you push

Azure DevOps

Connect your organization with a service principal.

  • Votes as a real reviewer: Approved or Waiting for author
  • Inline findings with suggested changes
  • A non-blocking otto/review status you can require in a branch policy
  • A fresh summary thread with every review
  • Comment /otto review to re-run anytime

Talk to Otto on the PR

Reply to any of its comments, or use a command. Otto answers in the thread and remembers what you've told it on that pull request.

  • @otto-detectiveAsk a question in any GitHub PR comment or thread
  • /otto reviewRun a fresh full review — even on a large PR
  • /otto re-reviewThe same, after you push changes
  • /otto explainExplain what the code does and why

Your team's rules

Set once in Otto's review settings.

  • Review instructions — Tell Otto what matters to your team — areas to focus on, conventions to enforce, or things to skip.

  • Review depth — Standard, Deep, or Max. Switch anytime; it applies to the next review.

  • Automatic reviews — On by default for the repositories you connect. Turn them off org-wide whenever you need to.

  • Comment style — On GitHub, keep one updated summary per PR or post a new one with each review.

Dependabot and Renovate PRs are reviewed too. Pull requests that change more than 100 files are skipped automatically — and aren't charged — unless someone comments /otto review.

Your AI writes the code. Otto Detective reviews it.

Claude Code, Cursor, Copilot, or by hand — however your team writes code, Otto reviews the pull request that comes out of it. It isn't another coding agent to adopt, and your team stays in control of the merge.

Works with any harness

Otto reviews the pull request, not the tool that wrote it — AI-assisted or by hand.

Hands fixes back

Every inline finding includes a prompt you can paste straight into your AI coding tool.

Never touches your branch

No commits, pushes, or merges. A suggestion only lands when someone on your team applies it.

Pricing

Pay per pull request. No seats.

Otto charges for the reviews it runs — never per person, and never in tokens. Choose how deep each review goes.

Standard

Focused reviews for everyday changes.

Deep

Default

Thorough reviews that trace changes across the codebase.

Max

The most thorough review, for critical code paths.

Deeper tiers use more capable models, so each review costs more. Switch depth anytime in your review settings.

  • Charged per pull request from prepaid credits — see what each PR cost in your dashboard
  • No per-seat licenses: your whole team gets reviews
  • New workspaces start with a free welcome credit
  • Top up anytime, or turn on auto-refill
  • Large PRs that Otto skips automatically aren't charged

FAQ

Questions, answered

Put Otto Detective on your next pull request

Install the GitHub App, pick your repositories, and Otto reviews the next pull request that opens.

Starts with a free welcome credit. No credit card required.