mrkeyoor.com_
Mon 05 Oct 07:14 UTC
AI Toolsevaluationupdated 05 Oct 2026

jev-review review

Jev Review is a local TypeScript workflow that asks TypeSafe Jev to review a Git branch diff or scan a JavaScript and TypeScript codebase. It screens files first, spends extra model calls on the strongest signals, and saves findings to a local dashboard for human review.

Verdict

Our Jev Review install took 3 seconds and npm audit found 0 known vulnerabilities, but the repository had no build or test target and whole-codebase review followed at most 8 signals. Try it on small JavaScript or TypeScript changes if you want to study staged AI review design. Do not use the current v0.1.0 code as a merge gate or assume an empty report means the codebase was cleared.

We ran it

Lab card: what happened when we ran jev-reviewScreenshot of jev-review (github.com/devagrawal09/jev-review)
Install✓ · 3s4 packages · 27 MB
Buildn/ano build script
Testsn/ano test script
Known vulns00 critical · 0 high · 0 moderate · 0 low (npm audit)
Repo29 files~1,851 lines of source · 0.2 MB · 0 CI workflows

Answers from our run

Does jev-review build from source?

Dependencies installed in 3 seconds (4 packages), and the project has no separate build step. We cloned commit 31f8960 into a clean Debian container with 3 CPUs and no project-specific setup.

Does jev-review have tests you can run?

Not through a standard command: the project exposes no test script or target that our harness could run.

Does jev-review have known vulnerabilities in its dependencies?

npm audit found none in the dependency tree at the time of our run.

Who should not use jev-review?

Go, Rust, Python, Java, or mixed-language repositories: the source discovery pattern accepts only JavaScript and TypeScript extensions.

What are the alternatives to jev-review?

PR-Agent, Semgrep, reviewdog. Our Jev Review install took 3 seconds and npm audit found 0 known vulnerabilities, but the repository had no build or test target and whole-codebase review followed at most 8 signals.

Setup3/5Tiny install, but Node 24 and a TypeSafe API key are required
Docs3/5Workflow is clear; language, cap, and dashboard risks need clarity
Community3/5671 stars and 7 open issues and PRs, with no later source push
Maturity1/5v0.1.0 has no tests, build target, CI workflow, or release

Who it’s for

TypeScript teams experimenting with structured model judgments instead of one large review prompt.
Developers who want separate diff-review and whole-codebase commands with a local report viewer.
Reviewers willing to treat model findings as prompts and verify them against the code.
Small repositories where an 8-signal follow-up budget can still cover the likely defects.

Who it’s NOT for

Go, Rust, Python, Java, or mixed-language repositories: the source discovery pattern accepts only JavaScript and TypeScript extensions.
Large codebases expecting every flagged concern to be investigated: the default workflow follows only the top 8 signals, and issue 7 reports 1,601 signals being left uninspected.
Teams that need local or open-weight inference: the current quick start requires a TypeSafe API key, while local model support remains an open request.
Release gates that require a maintained automated suite: our run found no test target, no build target, no tests directory, and no CI workflow.
Users who need to browse untrusted sites while the dashboard is open: the current server lacks the Host validation proposed in open pull request 6.

Setup reality

Our sandbox installed commit 31f8960 in 3 seconds, adding 4 packages and using 27 MB. There was no build script or target, so build was skipped. There was no test script or target, so tests were skipped. Npm audit found 0 known vulnerabilities.

The tool requires Node.js 24 or newer, Git, and a TYPESAFE_API_KEY. A diff review needs a Git repository and compares branch work with main or origin/main; full scans read tracked and unignored source files.

Only JavaScript and TypeScript extensions are discovered. Reports are stored locally and served on 127.0.0.1:4317. The current workflow caps follow-ups at 8 and profiles at 5, so cost control can also suppress coverage on a large scan.

Five risk dimensions feed a staged review

Jev Review screens each file for 5 dimensions: correctness, security, reliability, compatibility, and test gaps. Signals at or above a 0.7 probability move into a ranked queue. The workflow then profiles a small set of files, asks the model to locate evidence, scores severity, and assigns an owner when a finding merits review. This is more disciplined than sending an entire repository in one prompt.

The code keeps thresholds and orchestration outside the model. Severity uses a 0-to-3 rubric, evidence location needs at least 0.55 confidence, and 3 model calls can run concurrently. The final report records the matrix, selected profiles, followed signals, findings, and configuration. Those numbers help a reviewer see what the workflow considered. They do not show whether a discarded signal contained a defect.

The 8-signal cap can erase codebase-scan coverage

After screening, workflow.ts sorts every above-threshold signal and slices the list to MAX_FOLLOW_UPS, currently 8. That fixed budget may be sensible for a small branch diff. It is a poor match for a large repository because the command name promises a complete codebase scan while most signals can stop before evidence selection. The saved report counts the gap, but an empty findings array is easy to misread.

Open issue 7 supplies a concrete failure mode. In the reporter's 1,471-file scan, 1,609 signals crossed the threshold, only 8 were inspected, and 0 became findings. The remaining 1,601 were silently left out. Open pull request 8 proposes a configurable cap and a warning when it binds. That fix is not on the default branch we reviewed, so buyers should treat the limit as current behavior.

What happened when we ran it

Our measurement setup cloned commit 31f8960 into an unprivileged Debian container with 3 CPUs, 8 GB of RAM, Node 22, and no secrets. Installation succeeded in 3 seconds, adding 4 packages and occupying 27 MB. Npm audit reported 0 known vulnerabilities across critical, high, moderate, and low severities.

There was no build script or target, so the lab skipped that step. There was also no test script or target, and the repository had no tests directory, so no tests ran. Our scan found 0 CI workflow files and no Dockerfile. These absences fit the README's description of an experiment, but they leave changes to orchestration, file access, and report serving without an automated regression net on the reviewed commit.

The check command is useful, though narrower. It runs TypeScript type checking, verifies the intended dependency direction between folders, and syntax-checks the dashboard client. That can catch invalid imports or syntax. It does not exercise Git discovery, model failures, threshold behavior, report writes, or HTTP requests as end-to-end tests.

Node 24 and one hosted key are mandatory

The quick start requires Node.js 24 or newer, Git, and a TYPESAFE_API_KEY. There are separate commands for current-branch changes and all discovered source files. Saved variants write a report for the dashboard, which listens on 127.0.0.1:4317. The package is private, versioned 0.1.0, and has only one runtime dependency: the TypeSafe AI SDK.

There is no model-provider abstraction on the default branch. Open issue 9 asks for local open-weight model support, and open pull request 1 proposes an alternative gateway. Neither is shipped behavior. Teams with data residency rules should check what source leaves the machine, how the provider retains it, and whether secrets have been removed before sending a diff or full file.

Only JavaScript and TypeScript files enter the scan

SOURCE_FILE matches JS, JSX, TS, TSX, MJS, CJS, MTS, and CTS files. Full-codebase discovery uses Git to collect tracked and unignored files under the chosen scope. Files in Python, Go, Rust, Java, configuration formats, templates, and infrastructure definitions never reach the screening matrix. The current README says every non-ignored source file, which can overstate that boundary for a mixed repository.

File safety also has an open patch. Pull request 10 proposes protections against symbolic-link escapes, special files, and path swaps while reading a repository, plus atomic report writes. Those changes are not merged into commit 31f8960. Run the tool only on repositories you trust, under a user that cannot read unrelated secrets, until equivalent protections land and are tested.

Seven open threads show useful review but no shipped follow-up

GitHub listed 7 open issues and pull requests on October 5, 2026, including the scan cap, local model support, dashboard Host checks, and file-read hardening. The repository was created on September 16 and last pushed on September 17. It had 671 stars but no GitHub release. Recent discussion is active, while the default branch remains the initial v0.1.0 experiment.

Jev Review is worth reading for its staged prompts, explicit thresholds, and quiet local report. Its current operational result needs a narrower claim: it reviews a budgeted subset of JavaScript and TypeScript signals through one hosted provider. A 0-finding report can mean no defect survived the pipeline, or it can mean the relevant signal never entered the top 8. Human review must resolve that ambiguity.

Alternatives

ProjectWhat it isPick it when
PR-AgentAn AI pull-request assistant with multiple model providers and Git platform integrations.pick this instead when reviews need to run inside a hosted pull-request workflow.
SemgrepA static analyzer that applies explicit source rules without a model deciding what to inspect.pick this instead when repeatable policy checks and CI enforcement matter more than model judgment.
reviewdogA review annotation runner that turns existing linter output into pull-request feedback.pick this instead when you already trust your analyzers and mainly need clean review comments.

What people are saying

  1. [velocity-scout] NiazMorshed2007/jev-review
  2. [velocity-scout] devagrawal09/jev-review

Sources

  1. Jev Review repository
  2. Jev Review README
  3. Jev Review workflow configuration
  4. Codebase follow-up cap issue
  5. Dashboard Host validation pull request

More ai tools reviews

jev-experiments · OrcaBonsai-27B-Uncensored · NanoJev · uplifting-biomolecular-modeling · procedural-film · Dream-RSI · the whole board →