How to Automate Code Review with AI Agents
Set up an automated AI code review pipeline where one agent writes code and another reviews it — with practical examples and configuration.
Code review is one of the highest-value activities in software development. It catches bugs, enforces standards, and spreads knowledge across the team. It's also a bottleneck — reviews sit in queues while reviewers context-switch between their own work and incoming PRs.
AI agents can review code instantly. And with the right setup, you can automate the entire flow: write code with one agent, review it with another, fix issues, and re-review — all without manual intervention.
Here's how to set it up.
The basic pattern
Writer Agent → Review Agent → Writer Agent (fix) → Review Agent (approve)- The writer agent implements a feature or fix.
- On completion, the output is automatically sent to the review agent.
- The reviewer analyzes the changes and reports issues.
- Issues are routed back to the writer for fixes.
- The cycle repeats until the reviewer approves (or hits a round limit).
Step 1: Define the review criteria
The review agent needs clear criteria. Without them, it'll give generic feedback like "consider adding error handling" — not useful.
Good review prompts include specific criteria:
Review the changes for:
1. Correctness — Does the logic handle all cases, including edge cases?
2. Security — Are there SQL injection, XSS, or authentication bypass risks?
3. Performance — Are there N+1 queries, unnecessary allocations, or blocking calls?
4. Error handling — Are errors caught, logged, and propagated correctly?
5. Consistency — Does the code follow existing patterns in the codebase?
If all criteria pass, respond with "LGTM" (Looks Good To Me).
If issues found, list each one with the file path and line number.The "LGTM" keyword is important — it signals that the review passed, which stops the routing loop.
Step 2: Set up the writer agent
Start your writer agent with a focused task:
Implement rate limiting for the /api/auth/login endpoint.
Use a sliding window algorithm with a limit of 5 attempts per minute per IP.
Store the window in Redis using the existing Redis client at src/lib/redis.ts.Specific tasks produce specific changes, which get better reviews.
Step 3: Configure the routing connection
Connect the writer to the reviewer with these settings:
| Setting | Value | Why |
|---|---|---|
| Trigger | on-idle | Wait for the writer to fully finish before reviewing |
| Transform | ai-routing | AI generates a context-aware review prompt |
| Max rounds | 3 | Prevent infinite review loops |
| Stop keyword | LGTM | Terminate when the reviewer approves |
| Cooldown | 5s | Give agents enough time for complete responses |
The ai-routing transform is important here. It reads the writer agent's full response (via JSONL session resolution for Claude Code), understands what was implemented, and generates a review prompt that includes the specific files changed and the implementation context.
Step 4: Configure the reverse connection
For the review loop to work, you also need a connection from the reviewer back to the writer:
| Setting | Value | Why |
|---|---|---|
| Trigger | on-idle | Wait for the full review before routing back |
| Transform | ai-routing | Converts review findings into fix instructions |
| Max rounds | 3 | Same limit as forward direction |
| Stop keyword | LGTM | If reviewer approved, don't route back |
The reverse transform converts review comments into actionable fix instructions: "Fix the rate limiter bypass in src/middleware/rate-limit.ts:42 — the IP extraction doesn't handle X-Forwarded-For headers behind a proxy."
What to expect
A typical automated review cycle:
Round 1 (Writer → Reviewer):
- Writer implements rate limiting across 3 files.
- Router extracts the implementation summary and sends it to the reviewer.
- Reviewer finds 2 issues: missing X-Forwarded-For handling and no test for the 429 response.
Round 2 (Reviewer → Writer → Reviewer):
- Router converts review findings into fix instructions.
- Writer fixes both issues and adds the missing test.
- Router sends the updated implementation to the reviewer.
- Reviewer responds "LGTM — rate limiting correctly handles proxy headers and has test coverage."
Stop: The "LGTM" keyword triggers the stop condition. Total time: ~8 minutes, 2 rounds.
When automated review works best
- Focused changes — A single feature or bug fix with clear scope. Large, sprawling changes produce noisy reviews.
- Clear criteria — When you can define exactly what "good" looks like. Security reviews with OWASP criteria, performance reviews with specific SLA targets.
- Iterative refinement — When the first implementation is likely ~80% correct and needs polishing, not a complete rewrite.
When to use human review instead
- Architecture decisions — AI agents review implementation quality, not whether the approach is right.
- Cross-team impact — Changes that affect other teams need human context about organizational priorities.
- Sensitive code — Authentication, encryption, and financial logic deserve human eyes in addition to AI review.
Automated AI review is a complement to human review, not a replacement. Use it as a first pass that catches the mechanical issues, so human reviewers can focus on the strategic questions.
Tools for automated review
You can set up this pipeline manually with two terminal windows, but the manual handoff (copying review output, reformatting as fix instructions, pasting into the writer) is tedious.
MadoHub automates the entire flow. Place two terminal agents on the canvas, draw connections between them, configure the trigger/transform/stop settings, and start the writer. The routing system handles the rest — extraction, transformation, delivery, and loop termination.
Summary
Automated AI code review is one of the highest-ROI applications of multi-agent workflows. It's:
- Fast — Reviews happen in seconds, not hours.
- Consistent — The review criteria are the same every time.
- Iterative — Issues get fixed immediately, not in a follow-up PR.
- Complementary — Use it alongside human review for comprehensive coverage.
The setup takes 5 minutes. The time savings compound every day.