DiffRigorVerify what your coding agent missed. DiffRigor is an independent production-risk verifier for Python changes after a coding agent finishes a task. It is not a general-purpose AI style reviewer. Risk Review combines deterministic changed-symbol analysis, bounded production-first investigation, concrete changed-code and caller evidence, model analysis, and deterministic evidence/consistency checks before presenting a finding. DiffRigor 0.1 is an experimental pre-release. Findings require your judgment, and an empty result does not prove that a change is safe. InstallationDiffRigor requires VS Code 1.85 or newer. Once the pre-release is published, find DiffRigor in Extensions and choose Install Pre-Release. To install a supplied beta package, run Extensions: Install from VSIX…. Open a trusted local Git repository with Python changes, run DiffRigor: Configure Settings, and choose a model connection. Model configurationLocalThe default Local setup uses Ollama:
Install the default model with Local describes the connection mode, not a privacy guarantee. If you change the URL to a remote address, review data is sent there. In SSH or container sessions, OnlineOnline provides OpenRouter, Kilo, and Custom OpenAI-compatible endpoint presets. OpenRouter and Kilo always use their fixed preset endpoints. Custom requires you to enter a complete Each Online provider remembers its own model ID. Switching from OpenRouter to Kilo or Custom immediately restores the model last saved for that provider. OpenRouter defaults to The saved key is bound to the effective Online endpoint. Changing to a different effective Online endpoint discards the saved key and requires setting one for the new endpoint. Model guidance
The 7B model has completed the Risk Review structured-output flow successfully, but it may produce less complete reasoning or findings than the recommended 30B model. Model capability materially affects review quality. Local models provide privacy and cost advantages when they actually run locally, while stronger models may identify production risks that smaller models miss. OpenRouter and Kilo let you select compatible cloud models. Model quality and structured-output reliability vary, and DiffRigor may reject unsupported or inconsistent candidates instead of presenting them as validated findings. How Risk Review worksFor each diff, DiffRigor deterministically identifies changed Python symbols and allocates a bounded investigation set. Production files and production-file breadth are prioritized before additional production symbols and conventional test-only candidates. Documentation-only changes are skipped. Each selected symbol receives a bounded evidence bundle containing changed code and, where conservatively discoverable, direct caller context. The selected model analyzes each investigation independently. DiffRigor then checks evidence references and consistency, rejects unsupported historical-contract, caller-usage, signature, and related claims, maps accepted findings back to reviewed source snapshots, consolidates overlapping findings, and finally applies the user's category, confidence, and maximum-finding filters. A partial review means the bounded set did not cover every changed symbol or some investigations failed; it is never presented as exhaustive repository coverage. Untouched settings enable Review workflows
The Risk Review view also supports unstaged changes. New untracked files must be staged to appear in a Git diff. In multi-root workspaces, DiffRigor reviews the first workspace folder. Branch mode uses the first available base from Open a finding to inspect its evidence, review any resulting fix, and run DiffRigor again. If a model returns malformed structured output, DiffRigor may make at most one format-repair request per investigation response, using the same selected model. Privacy basics
See the packaged PRIVACY.md for details. LimitationsRisk Review is Python-focused, bounded, and heuristic. Its changed-symbol and conservative textual caller analysis can produce partial coverage. It does not semantically resolve every import or alias, build a repository-wide dependency graph, follow arbitrary multi-hop dependencies, or guarantee exhaustive findings. DiffRigor does not read coding-agent sessions or original tasks, detect AI authorship, know which tests were run, verify task completeness, or replace human review and testing. SupportAfter publication, report installation problems, crashes, false positives, and missed risks through the DiffRigor Marketplace listing's Q&A. Use a minimal synthetic example; do not post proprietary code, API keys, repository identifiers, or raw verbose logs. See the packaged SUPPORT.md. LicenseDiffRigor is proprietary software. DiffRigor 0.1 is available at no charge for personal and internal commercial software-development use. See the packaged LICENSE.txt for the complete terms and THIRD_PARTY_NOTICES.txt for bundled components. |