# What Kind of Code Reviews Does code‑review‑graph Analyze? Change‑Impact Analysis Explained

> code-review-graph analyzes risk-scored change-impact, mapping code change propagation and potential risk. Discover how it enhances your review process beyond simple style checks.

- Repository: [Tirth Kanani/code-review-graph](https://github.com/tirth8205/code-review-graph)
- Tags: deep-dive
- Published: 2026-08-17

---

**code‑review‑graph performs risk‑scored change‑impact analysis that maps how code changes propagate through your codebase and scores their potential risk rather than checking style or syntax line‑by‑line.**

This open‑source tool, maintained at **tirth8205/code‑review‑graph**, transforms traditional code reviews by focusing on **what changed, how far it reaches, and how risky that propagation is**. Instead of manual diff inspection, reviewers receive structured reports with transitive impact maps, numeric risk scores, and targeted context snippets pulled from the underlying knowledge graph.

## Change‑Impact‑Focused Reviews vs. Traditional Approaches

Code‑review‑graph diverges sharply from conventional review tools. Rather than flagging linting errors or formatting issues, it answers three critical questions for every pull request:

1. **What symbols changed?** — Functions, methods, classes, and types across all supported languages.
2. **What depends on those changes?** — Upstream callers and downstream callees discovered via graph traversal.
3. **How dangerous is this change?** — A composite risk score derived from change frontier size, test coverage gaps, and historical change density.

This analysis is **language‑agnostic** because the tool builds a uniform knowledge graph abstracting symbols, imports, and type information from Python, Java, Kotlin, PHP, Rust, TypeScript, and other languages.

## Core Tools: detect_changes_tool and get_review_context_tool

The review workflow centers on two primary tools implemented in [`code_review_graph/main.py`](https://github.com/tirth8205/code-review-graph/blob/main/code_review_graph/main.py).

### detect_changes_tool: The Risk Engine

The **`detect_changes_tool`** (defined at [L633](https://github.com/tirth8205/code-review-graph/blob/main/code_review_graph/main.py#L633)) parses any Git diff and produces a structured impact report. It performs:

- **Symbol extraction** — Identifies every function, method, and type modified in the diff.
- **Graph mapping** — Links changed symbols to their callers, callees, and data‑flow neighbors.
- **Transitive traversal** — Walks the graph to surface the full **impact frontier** of potentially affected code.
- **Risk scoring** — Assigns a numeric 0‑100 score based on frontier size, uncovered tests, and historical change patterns.
- **Test‑gap detection** — Flags missing unit or integration tests for changed paths.

Run it directly from Python:

```python
from code_review_graph.main import detect_changes_tool

# `diff` accepts a Git diff string or path to a .diff file

report = await detect_changes_tool(diff=my_git_diff, detail_level="standard")

print(report.changed_symbols)   # List of symbols touched

print(report.impact_frontier)   # Transitive callees / callers

print(report.risk_score)        # Numeric rating 0-100

print(report.test_gaps)         # Uncovered tests to add

```

### get_review_context_tool: Context Enrichment

After scoring, the **`get_review_context_tool`** fetches the most relevant source snippets, documentation, and design‑level abstractions to build a **"what‑to‑look‑for" summary**. This prevents reviewers from drowning in full‑file context.

```python
from code_review_graph.main import get_review_context_tool

context = await get_review_context_tool(
    symbols=report.impact_frontier,
    max_snippets=5
)

for snippet in context.snippets:
    print(snippet)

```

Per the [LLM‑optimized reference](https://github.com/github/tirth8205/code-review-graph/blob/main/code_review_graph/docs/LLM-OPTIMIZED-REFERENCE.md#L23), these tools chain with `get_affected_flows_tool` to generate a **blast‑radius table** pairing risk scores with concrete code locations.

## Starting the MCP Server with Review Tools

To expose the complete review toolchain, serve the MCP with the specific tools enabled:

```bash
code-review-graph serve \
  --tools query_graph_tool,semantic_search_nodes_tool,detect_changes_tool,get_review_context_tool

```

This configuration activates the graph query, semantic search, change detection, and context retrieval capabilities needed for full‑spectrum code reviews.

## Documentation and Workflow Integration

The project's documentation consistently frames these capabilities as **risk‑scored change impact analysis for code review**:

- The **README** ([L490](https://github.com/tirth8205/code-review-graph/blob/main/README.md#L490)) lists this as the primary feature in its capabilities table.
- The **USAGE guide** ([L112](https://github.com/tirth8205/code-review-graph/blob/main/docs/USAGE.md#L112)) demonstrates tool integration patterns.
- The **review‑changes skill** ([L12](https://github.com/tirth8205/code-review-graph/blob/main/skills/review-changes/SKILL.md#L12)) prescribes the standard workflow: run `detect_changes_tool`, inspect the diff‑impact report, then drill down with context tools.

## Summary

- **code‑review‑graph analyzes change‑impact**, not style or syntax — it traces how modifications propagate through your codebase.
- **Risk scoring** (0‑100) combines frontier size, test coverage, and historical density to prioritize reviewer attention.
- **Language‑agnostic analysis** works across Python, Java, Kotlin, PHP, Rust, TypeScript, and more via a unified symbol graph.
- **Two‑tool workflow**: `detect_changes_tool` generates the impact report; `get_review_context_tool` surfaces relevant snippets.
- **Designed for CI integration** — async Python API and MCP server enable automated review pipelines.

## Frequently Asked Questions

### Does code‑review‑graph check code style or formatting?

No. The tool deliberately excludes style checks, linting, or formatting rules. It focuses exclusively on **semantic change impact** — how modifications affect program behavior through call‑flow and data‑flow relationships. For style enforcement, integrate separate tools like Black, Prettier, or ESLint.

### What languages does the change‑impact analysis support?

The analysis is **language‑agnostic** due to its graph‑based architecture. The underlying knowledge graph abstracts symbols, imports, and type information uniformly. Explicitly supported languages include **Python, Java, Kotlin, PHP, Rust, and TypeScript**, with extensibility for additional languages via the graph schema.

### How is the risk score calculated?

The risk score (0‑100) derives from three weighted factors: **size of the change frontier** (how many symbols are transitively affected), **presence of uncovered tests** (gaps in unit or integration coverage), and **historical change density** (how frequently this code has changed before). High scores indicate changes requiring deeper scrutiny.

### Can I use this in a CI/CD pipeline?

Yes. The `detect_changes_tool` exposes an **async Python API** suitable for CI steps. Pass a Git diff string or `.diff` file path, await the report, and gate merges on risk thresholds or test‑gap counts. The MCP server mode also enables integration with AI‑powered review agents.