Pull Request Scanner That Flags Risky AI Code
GitHub App that flags risky AI-authored code — hallucinated deps, permission jumps, thin comments — as a required check before merge.
A staff engineer opens a 400-line pull request at 6:12 p.m. The description says “small refactor.” Half the hunks were written by Cursor. A Copilot-authored commit sits underneath. The reviewer skims the green, trusts the test that the model also wrote, and hits merge so they can eat dinner. Two weeks later production dies on a package that never existed on npm, a permission flag that quietly went from `read` to `admin`, and a 90-line function whose only comment is “handle edge cases.” The review tool they already pay for left a dozen style nits. It never asked whether a model was guessing.
Built for Developers, Solo Founders.
$10.12B AI code tools in 2026 → $91.09B by 2035 — parent TAM; MergeGate sells the merge-gate, not the autocomplete (Ideabrowser idea 8902 highlight justification).
Suggested stack: GitHub App + Octokit, Claude + GPT-4o, Postgres, BullMQ + Redis, Stripe Billing, Fly.io or Vercel. Weekend scope: about 8 hours.
The Problem
A staff engineer opens a 400-line pull request at 6:12 p.m. The description says “small refactor.” Half the hunks were written by Cursor. A Copilot-authored commit sits…
The Solution
MergeGate is a GitHub App that treats AI-authored code as a distinct risk class, not as “more code.” It reads commit and editor metadata from assistants like Cursor and Copilot to…
Market Research
$10.12B AI code tools in 2026 → $91.09B by 2035 — parent TAM; MergeGate sells the merge-gate, not the autocomplete (Ideabrowser idea 8902 highlight justification).
Competitive Landscape
CodeRabbit — Category leader for AI PR review. Deep comments, language coverage, learning per repo. Reviews the whole diff for quality; does not isolate AI-authored hunks or treat…
Business Model
OSS / Free ($0) — Public repos, origin labeling, standard detectors, MergeGate comments; no required-check enforcement on private repos
Recommended Tech Stack
GitHub App + Octokit — `pull_request` and `check_run` webhooks, signed payloads, Checks API for the required status. Installation tokens scoped per org. Marketplace listing is the…
AI Prompts to Build This
Copy these build prompts into Claude, Cursor, or your AI coding tool. Create a free account to unlock the full research behind them.
1. Project Setup
Build the weekend MVP of "MergeGate": a GitHub App that flags risky AI-authored code on a pull request as a required check. Stack: Next.js (App Router) with TypeScript, Supabase (Postgres, Row Level Security, Auth with GitHub sign-in), Octokit with GitHub App authentication, Claude (Anthropic API) for the classification. The webhook route replies within a second and does its work after the response. Deploy on Vercel. Tables (Row Level Security on: the dashboard reads only the installations the signed-in user belongs to): - installations(id, account_login) - repos(id, installation_id, full_name) - pull_requests(id, repo_id, number, head_sha) - hunks(id, pr_id, path, start_line, end_line, origin, assistant) where origin is one of ai, human, unknown and assistant is cursor, copilot or other - flags(id, hunk_id, kind, confidence, reason, status, dismissed_reason) where kind is one of hallucinated_dep, permission_escalation, thin_comment_dense_logic and status is one of open, accepted, dismissed - check_runs(id, pr_id, github_check_id, conclusion) Screens: /login, /repos (installed repos and recent pull requests). Env vars (names only): NEXT_PUBLIC_SUPABASE_URL, NEXT_PUBLIC_SUPABASE_ANON_KEY, SUPABASE_SERVICE_ROLE_KEY (server only), GITHUB_APP_ID, GITHUB_PRIVATE_KEY, GITHUB_WEBHOOK_SECRET, ANTHROPIC_API_KEY. Do not build: billing, plans or seat mapping, Slack alerts, a job queue or Redis, a second AI model, a cost dashboard, anything on the dashboard that is not a read-model of GitHub state. Done when: npm run dev starts, the app installs on a test repo, and the six tables exist with Row Level Security on.
2. Core Feature
Build the one feature that proves MergeGate: a required check that fails on the lines a model invented. 1. On pull_request opened and synchronize, verify the webhook signature, reply at once, then fetch the diff and the commit list. 2. Classify each hunk's origin from commit trailers and author metadata from Cursor or Copilot when present. Fall back to commit-message patterns and known assistant co-author emails. Never claim certainty without metadata. 3. Run three detectors: (a) hallucinated dependencies: parse added imports and package.json changes, look the names up in npm and PyPI, and flag names that do not exist or are not in the lockfile. (b) permission escalations: diff rules for IAM, RBAC, GitHub Actions permissions and auth middleware going from read to write or admin. (c) thin comments over dense logic: line density against comment ratio, on AI-origin hunks only. 4. Each flag gets a kind, a confidence from 0 to 1, a reason under 200 characters and a suggested reviewer. If the top confidence is 0.7 or more, fail the check. Otherwise pass with a summary comment. Post inline annotations. 5. A Dismiss link needs a signed-in member and a written reason, which is stored. Rules: skip the model when the registry lookup or a diff rule already decided. Write tests for: a hallucinated package, a real package, a permission widen, a permission left unchanged, an AI hunk with no comments, a human hunk with dense logic that must NOT be flagged, and a replayed webhook that must not double-post. Done when: a test pull request that imports a package that does not exist fails the "MergeGate AI-origin" check with an inline note, and replaying its webhook changes nothing.
3. Landing Page
Build a one-page landing site for MergeGate, a required check for AI-authored code. Hero: "The required check for AI-authored code." Sub: "A review tool reads the diff. MergeGate flags the lines a model invented." One button: Install the GitHub App, which joins the waitlist. Sections: a 6:12 p.m. merge story, how it works in four steps (install, classify AI-origin hunks, score the risky patterns, block or escalate), three detector cards (hallucinated dependencies, permission escalations, thin comments over dense logic), and a short FAQ on false positives and what it can see. Waitlist: store the email in a waitlist table in Supabase. No other service. Style: Geist, near-black text on off-white, one lime accent. Done when: the page renders on a phone and a submitted email appears in the waitlist table.
4. Branding Package
Use a design or image tool for this one. A coding agent cannot draw a logo. Brand for MergeGate: a wordmark and an icon that suggest a gate or a checkpoint. Colors: near-black, off-white and one lime accent. Type: Geist for the interface and a mono for file paths. Deliverables: wordmark, icon, a pass and a fail check badge that differ by shape and not only color, and one launch graphic. Done when: each deliverable is saved in one folder and the two badges are distinguishable without color.