What Kind of Code Reviews Does code‑review‑graph Analyze? Change‑Impact Analysis Explained
code‑review‑graph performs risk‑scored change‑impact analysis that maps how code changes propagate through your codebase and scores their potential risk rather than checking style or syntax line‑by‑line.
This open‑source tool, maintained at tirth8205/code‑review‑graph, transforms traditional code reviews by focusing on what changed, how far it reaches, and how risky that propagation is. Instead of manual diff inspection, reviewers receive structured reports with transitive impact maps, numeric risk scores, and targeted context snippets pulled from the underlying knowledge graph.
Change‑Impact‑Focused Reviews vs. Traditional Approaches
Code‑review‑graph diverges sharply from conventional review tools. Rather than flagging linting errors or formatting issues, it answers three critical questions for every pull request:
- What symbols changed? — Functions, methods, classes, and types across all supported languages.
- What depends on those changes? — Upstream callers and downstream callees discovered via graph traversal.
- How dangerous is this change? — A composite risk score derived from change frontier size, test coverage gaps, and historical change density.
This analysis is language‑agnostic because the tool builds a uniform knowledge graph abstracting symbols, imports, and type information from Python, Java, Kotlin, PHP, Rust, TypeScript, and other languages.
Core Tools: detect_changes_tool and get_review_context_tool
The review workflow centers on two primary tools implemented in code_review_graph/main.py.
detect_changes_tool: The Risk Engine
The detect_changes_tool (defined at L633) parses any Git diff and produces a structured impact report. It performs:
- Symbol extraction — Identifies every function, method, and type modified in the diff.
- Graph mapping — Links changed symbols to their callers, callees, and data‑flow neighbors.
- Transitive traversal — Walks the graph to surface the full impact frontier of potentially affected code.
- Risk scoring — Assigns a numeric 0‑100 score based on frontier size, uncovered tests, and historical change patterns.
- Test‑gap detection — Flags missing unit or integration tests for changed paths.
Run it directly from Python:
from code_review_graph.main import detect_changes_tool
# `diff` accepts a Git diff string or path to a .diff file
report = await detect_changes_tool(diff=my_git_diff, detail_level="standard")
print(report.changed_symbols) # List of symbols touched
print(report.impact_frontier) # Transitive callees / callers
print(report.risk_score) # Numeric rating 0-100
print(report.test_gaps) # Uncovered tests to add
get_review_context_tool: Context Enrichment
After scoring, the get_review_context_tool fetches the most relevant source snippets, documentation, and design‑level abstractions to build a "what‑to‑look‑for" summary. This prevents reviewers from drowning in full‑file context.
from code_review_graph.main import get_review_context_tool
context = await get_review_context_tool(
symbols=report.impact_frontier,
max_snippets=5
)
for snippet in context.snippets:
print(snippet)
Per the LLM‑optimized reference, these tools chain with get_affected_flows_tool to generate a blast‑radius table pairing risk scores with concrete code locations.
Starting the MCP Server with Review Tools
To expose the complete review toolchain, serve the MCP with the specific tools enabled:
code-review-graph serve \
--tools query_graph_tool,semantic_search_nodes_tool,detect_changes_tool,get_review_context_tool
This configuration activates the graph query, semantic search, change detection, and context retrieval capabilities needed for full‑spectrum code reviews.
Documentation and Workflow Integration
The project's documentation consistently frames these capabilities as risk‑scored change impact analysis for code review:
- The README (L490) lists this as the primary feature in its capabilities table.
- The USAGE guide (L112) demonstrates tool integration patterns.
- The review‑changes skill (L12) prescribes the standard workflow: run
detect_changes_tool, inspect the diff‑impact report, then drill down with context tools.
Summary
- code‑review‑graph analyzes change‑impact, not style or syntax — it traces how modifications propagate through your codebase.
- Risk scoring (0‑100) combines frontier size, test coverage, and historical density to prioritize reviewer attention.
- Language‑agnostic analysis works across Python, Java, Kotlin, PHP, Rust, TypeScript, and more via a unified symbol graph.
- Two‑tool workflow:
detect_changes_toolgenerates the impact report;get_review_context_toolsurfaces relevant snippets. - Designed for CI integration — async Python API and MCP server enable automated review pipelines.
Frequently Asked Questions
Does code‑review‑graph check code style or formatting?
No. The tool deliberately excludes style checks, linting, or formatting rules. It focuses exclusively on semantic change impact — how modifications affect program behavior through call‑flow and data‑flow relationships. For style enforcement, integrate separate tools like Black, Prettier, or ESLint.
What languages does the change‑impact analysis support?
The analysis is language‑agnostic due to its graph‑based architecture. The underlying knowledge graph abstracts symbols, imports, and type information uniformly. Explicitly supported languages include Python, Java, Kotlin, PHP, Rust, and TypeScript, with extensibility for additional languages via the graph schema.
How is the risk score calculated?
The risk score (0‑100) derives from three weighted factors: size of the change frontier (how many symbols are transitively affected), presence of uncovered tests (gaps in unit or integration coverage), and historical change density (how frequently this code has changed before). High scores indicate changes requiring deeper scrutiny.
Can I use this in a CI/CD pipeline?
Yes. The detect_changes_tool exposes an async Python API suitable for CI steps. Pass a Git diff string or .diff file path, await the report, and gate merges on risk thresholds or test‑gap counts. The MCP server mode also enables integration with AI‑powered review agents.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →