{"_id":"@avinashchby/aireview","_rev":"2-442d75f1e859c401dc239b33a0b862ba","name":"@avinashchby/aireview","dist-tags":{"latest":"0.1.1"},"versions":{"0.1.0":{"name":"@avinashchby/aireview","version":"0.1.0","keywords":["linting","static-analysis","ai","llm","code-review","hallucination-detection","eslint","code-quality"],"author":{"name":"Avinash Chaubey"},"license":"MIT","_id":"@avinashchby/aireview@0.1.0","maintainers":[{"name":"avinashchby","email":"avinashchby@gmail.com"}],"homepage":"https://github.com/avinashchaubey/aireview#readme","bugs":{"url":"https://github.com/avinashchaubey/aireview/issues"},"bin":{"aireview":"bin/aireview.js"},"dist":{"shasum":"700077ebbc59fbf0d15ed6e937bcf408f26c49af","tarball":"https://registry.npmjs.org/@avinashchby/aireview/-/aireview-0.1.0.tgz","fileCount":100,"integrity":"sha512-IYdmi06+gb0qLw/i9Gs3/+izXbNGMyYIHHcN/jdhmARk44AZRRLVSmuzXsK0hBigij071xNh24okjZ7zEUKC1g==","signatures":[{"sig":"MEUCIQDGVPVt38qrvTIKLYH6khhYi51mYbm3J6zUezwXTmYSUAIgHliKwaGdmRJR+P4fi8NuWY1u1fEbwhneVxdVHdsgyG0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":226400},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"gitHead":"fefc76e54b3a93f804e86842277f9aea6f7b14e3","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc","test:watch":"vitest","prepublishOnly":"npm run build && npm test"},"_npmUser":{"name":"avinashchby","email":"avinashchby@gmail.com"},"repository":{"url":"git+https://github.com/avinashchaubey/aireview.git","type":"git"},"_npmVersion":"11.8.0","description":"Catch what your AI missed -- static analysis for LLM-generated code","directories":{},"_nodeVersion":"25.5.0","dependencies":{"chalk":"^5.4.1","ignore":"^7.0.3","commander":"^12.1.0","fast-glob":"^3.3.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.9","typescript":"^5.7.3","@types/node":"^22.13.14"},"_npmOperationalInternal":{"tmp":"tmp/aireview_0.1.0_1773907183269_0.9781167888230717","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@avinashchby/aireview","version":"0.1.1","description":"Catch what your AI missed -- static analysis for LLM-generated code","author":{"name":"Avinash Chaubey"},"repository":{"type":"git","url":"git+https://github.com/avinashchaubey/aireview.git"},"homepage":"https://github.com/avinashchaubey/aireview#readme","bugs":{"url":"https://github.com/avinashchaubey/aireview/issues"},"main":"dist/index.js","types":"dist/index.d.ts","bin":{"aireview":"bin/aireview.js"},"scripts":{"build":"tsc","test":"vitest run","test:watch":"vitest","lint":"tsc --noEmit","prepublishOnly":"npm run build && npm test"},"keywords":["linting","static-analysis","ai","llm","code-review","hallucination-detection","eslint","code-quality"],"license":"MIT","engines":{"node":">=18.0.0"},"dependencies":{"chalk":"^5.4.1","commander":"^12.1.0","fast-glob":"^3.3.3","ignore":"^7.0.3","typescript":"^5.7.3"},"devDependencies":{"@types/node":"^22.13.14","vitest":"^3.0.9"},"gitHead":"a1c4b7c60851d571b8cdf6516b34bc10e545b8ad","_id":"@avinashchby/aireview@0.1.1","_nodeVersion":"25.5.0","_npmVersion":"11.8.0","dist":{"integrity":"sha512-YoAGU6tAgjPDKDCoEnna+Ysp68AeuK/giqgqjWoa5iaM1oZh7WqgNQmzAts/4ZzhvRSwN9qI+43EA73JYM/4eQ==","shasum":"1fc98bb241b3af37d1b168717a0b3a99aa7a3f62","tarball":"https://registry.npmjs.org/@avinashchby/aireview/-/aireview-0.1.1.tgz","fileCount":100,"unpackedSize":226400,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQCnu/MLb+BBQgIw1YrIrbp3Kc3F8q0BhVSp6BPxbtXPNQIgdsRndNbf2Ivt8P06WOARNR54wG1GiSVXH+uer2152E8="}]},"_npmUser":{"name":"avinashchby","email":"avinashchby@gmail.com"},"directories":{},"maintainers":[{"name":"avinashchby","email":"avinashchby@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/aireview_0.1.1_1773972687589_0.5567471394554062"},"_hasShrinkwrap":false}},"time":{"created":"2026-03-19T07:59:43.185Z","modified":"2026-03-20T02:11:27.863Z","0.1.0":"2026-03-19T07:59:43.458Z","0.1.1":"2026-03-20T02:11:27.746Z"},"bugs":{"url":"https://github.com/avinashchaubey/aireview/issues"},"author":{"name":"Avinash Chaubey"},"license":"MIT","homepage":"https://github.com/avinashchaubey/aireview#readme","keywords":["linting","static-analysis","ai","llm","code-review","hallucination-detection","eslint","code-quality"],"repository":{"type":"git","url":"git+https://github.com/avinashchaubey/aireview.git"},"description":"Catch what your AI missed -- static analysis for LLM-generated code","maintainers":[{"name":"avinashchby","email":"avinashchby@gmail.com"}],"readme":"# aireview\n\n**Catch what your AI missed.** Static analysis for LLM-generated code -- no API keys, no cloud, no cost.\n\n[![npm version](https://img.shields.io/npm/v/aireview.svg)](https://www.npmjs.com/package/aireview)\n[![license](https://img.shields.io/npm/l/aireview.svg)](https://github.com/avinashchaubey/aireview/blob/main/LICENSE)\n[![node](https://img.shields.io/node/v/aireview.svg)](https://nodejs.org)\n\n```bash\nnpx aireview .\n```\n\n```\nsrc/api.ts (confidence: 42%)\n  ✗ 3:1   'openai-functions' is a commonly hallucinated package  [phantom-imports]\n    | import { createFunction } from 'openai-functions';\n\n  ✗ 14:5  'fs.readFileAsync' does not exist  [hallucinated-apis]\n    | const data = await fs.readFileAsync('config.json');\n    Fix: Use 'fs.promises.readFile'\n\n  ✗ 22:0  eval() is a code injection vector  [security-antipatterns]\n    | const result = eval(userInput);\n\n  ⚠ 28:1  Hedging comment: \"adjust as needed\"  [confidence-patterns]\n    | // adjust as needed for your use case\n\n---\nScanned 12 files in 38ms\nFound 3 errors, 1 warning\n```\n\n## Why this exists\n\nLLMs write confident-looking code that compiles, passes a glance review, and breaks in production. The failure modes are predictable:\n\n- **Phantom imports** -- packages that sound right but don't exist on npm/PyPI\n- **Hallucinated APIs** -- `fs.readFileAsync()`, `array.flatten()`, `dict.has_key()` -- methods that were never real or were removed years ago\n- **Placeholder stubs** -- empty function bodies, `// TODO` comments, `throw new Error(\"Not implemented\")` hidden behind working-looking signatures\n- **Security holes** -- `eval()`, SQL string concatenation, hardcoded API keys -- patterns LLMs reproduce from training data without understanding the risk\n- **Swallowed errors** -- `catch(e) {}`, bare `except:`, `.catch(() => {})` -- silent failure modes that make debugging impossible\n\nThese patterns are hard to catch in code review because they look intentional. `aireview` knows the specific shapes of LLM mistakes and flags them before they ship.\n\n**Zero API calls.** Pure AST parsing and pattern matching. Runs in milliseconds, works offline, costs nothing.\n\n## Install\n\n```bash\nnpx aireview .              # run without installing\nnpm install -g aireview     # or install globally\n```\n\nRequires Node.js >= 18.\n\n## Usage\n\n```bash\naireview .                              # scan current directory\naireview src/api.ts                     # scan a specific file\naireview src/ lib/                      # scan multiple paths\naireview --diff                         # scan staged git changes\naireview --diff HEAD~1                  # scan last commit\naireview --ci                           # CI mode: exit 1 if errors found\naireview --format json                  # JSON output for tooling\naireview --fix                          # auto-fix safe issues\naireview --severity error               # only errors, skip warnings/info\naireview --ignore phantom-imports       # skip specific rules\n```\n\n## Detection rules\n\n| Rule | Catches | Severity |\n|------|---------|----------|\n| `phantom-imports` | Imports of packages not in your dependency file, known hallucinated package names | warning/error |\n| `hallucinated-apis` | `fs.readFileAsync()`, `array.flatten()`, `new Buffer()`, `dict.has_key()`, 30+ more | error |\n| `placeholder-code` | TODO/FIXME, empty functions, `NotImplementedError`, `// ...` elisions | warning/error |\n| `confidence-patterns` | Generic variable names (`data`, `result`, `temp`), hedging comments, inconsistent style | info/warning |\n| `security-antipatterns` | `eval()`, `new Function()`, SQL injection, hardcoded secrets, disabled TLS | error |\n| `type-safety` | `any` overuse, `as any` casts, `@ts-ignore`, `@ts-nocheck`, loose equality | warning/error |\n| `error-handling` | Empty catch blocks, catch-only-logs, bare `except:`, missing `.catch()` | error/warning |\n\n## Configuration\n\nCreate `.aireviewrc.json` in your project root:\n\n```json\n{\n  \"rules\": {\n    \"phantom-imports\": \"error\",\n    \"hallucinated-apis\": \"error\",\n    \"placeholder-code\": \"warn\",\n    \"confidence-patterns\": \"off\",\n    \"security-antipatterns\": \"error\",\n    \"type-safety\": \"warn\",\n    \"error-handling\": \"error\"\n  },\n  \"ignore\": [\"*.test.ts\", \"*.spec.js\"]\n}\n```\n\nOr add an `\"aireview\"` key to your `package.json`.\n\n## GitHub Actions\n\n```yaml\nname: AI Code Review\non: [pull_request]\n\njobs:\n  aireview:\n    runs-on: ubuntu-latest\n    steps:\n      - uses: actions/checkout@v4\n        with:\n          fetch-depth: 0\n\n      - uses: actions/setup-node@v4\n        with:\n          node-version: '20'\n\n      - name: Run aireview\n        run: npx aireview --diff origin/main --ci\n```\n\nFindings appear as inline annotations on the PR diff. Use `--format json` to pipe into other tools.\n\n## Programmatic API\n\n```typescript\nimport { scan } from 'aireview';\n\nconst result = await scan({\n  paths: ['src/'],\n  severity: 'warning',\n  ignore: ['confidence-patterns'],\n});\n\nfor (const file of result.files) {\n  console.log(`${file.filePath}: ${file.confidenceScore}% confidence`);\n  for (const finding of file.findings) {\n    console.log(`  ${finding.line}:${finding.column} ${finding.message}`);\n  }\n}\n```\n\n## Supported languages\n\n- JavaScript (`.js`, `.jsx`) -- TypeScript compiler API\n- TypeScript (`.ts`, `.tsx`) -- TypeScript compiler API\n- Python (`.py`) -- regex-based parser (no native dependencies)\n\nDesigned for extensibility. Add a language by implementing a parser that returns `ParserResult` and registering rules.\n\n## License\n\nMIT\n","readmeFilename":"README.md"}