A developer utility web app: paste JavaScript/PHP code (or link a GitHub file), and get AI-generated structural improvement notes, security vulnerability detection, and refactoring suggestions — with results exportable as Markdown or PDF.
- Frontend: React + Vite, CodeMirror 6 (syntax-highlighted editor)
- Backend: Node.js + Express,
@anthropic-ai/sdkfor the LLM call - Database: SQLite (via
better-sqlite3) — zero-config, single file - Export: Markdown (raw text) and PDF (via
pdfkit)
ai-code-review-assistant/
├── backend/ Express API
│ ├── server.js Entry point
│ ├── src/
│ │ ├── config/db.js SQLite connection + schema bootstrap
│ │ ├── db/schema.sql Table definitions (mirrors /database/schema.sql)
│ │ ├── routes/ analyze.js, history.js, reports.js
│ │ ├── services/ llmService, githubService, exportService, promptTemplates
│ │ └── middleware/ errorHandler.js
│ └── .env.example
├── frontend/ React app
│ └── src/
│ ├── components/ CodeEditor, AnalysisReport, FindingCard, ExportButtons, etc.
│ ├── api/client.js Axios wrapper for the backend API
│ └── App.jsx
├── database/
│ ├── schema.sql Canonical schema reference
│ └── seed.sql Optional sample data
└── README.md
- Input: paste a JS/PHP snippet into the CodeMirror editor, or paste a GitHub file URL
(
https://github.com/{owner}/{repo}/blob/{branch}/{path}) — the backend fetches the raw file. - Analyze: clicking "Analyze Code" sends the snippet (with line numbers) to the backend,
which calls the Anthropic API using a system prompt tuned for security vulnerability
detection (SQLi, XSS, insecure deserialization, hardcoded secrets, etc. — mapped to CWE IDs
where applicable), structural/code-quality issues, and refactor suggestions. The model
returns strict JSON, which is persisted as structured
findingsrows. - Review: results are shown as a scored summary (structural + security scores out of 100) plus a severity-sorted list of findings, each with a description, line reference, and a concrete suggested fix.
- Export: "Export Markdown" / "Export PDF" generate a downloadable report file containing the summary, scores, all findings, and the original code.
- History: past submissions/analyses are listed in a sidebar and can be reopened at any time.
cd backend
cp .env.example .env
# edit .env and set ANTHROPIC_API_KEY (get one at https://console.anthropic.com/)
npm install
npm run db:init # creates the SQLite file + applies schema.sql
npm run dev # starts on http://localhost:4000cd frontend
cp .env.example .env # optional — defaults to same-origin /api via the Vite dev proxy
npm install
npm run dev # starts on http://localhost:5173Open http://localhost:5173 in your browser.
sqlite3 backend/data/code_review.db < database/seed.sql| Method | Path | Description |
|---|---|---|
| POST | /api/analyze |
Submit code (paste or GitHub URL) for AI analysis |
| GET | /api/history |
List recent submissions + latest analysis status |
| GET | /api/history/:analysisId |
Full detail for one analysis |
| POST | /api/reports/:analysisId/markdown |
Generate a Markdown report, returns download URL |
| POST | /api/reports/:analysisId/pdf |
Generate a PDF report, returns download URL |
| GET | /api/reports/download/:fileName |
Download a previously generated report file |
| GET | /api/health |
Health check |
- The
ANTHROPIC_API_KEYmust be supplied by whoever runs the app — it is never hardcoded or shipped with this project. express-rate-limitcaps/api/analyzeat 10 requests/minute per client to protect against runaway LLM API costs; adjust inbackend/server.jsas needed.- The GitHub URL fetch supports public files via
raw.githubusercontent.com; setGITHUB_TOKENinbackend/.envto raise rate limits or access private repos you have access to. - To add more languages, extend the
languageCHECK constraint inschema.sql, add a CodeMirror language extension on the frontend, and update the prompt inpromptTemplates.js.

