Skip to content
| Marketplace
Sign in
Visual Studio Code>Linters>DiffRigorNew to Visual Studio Code? Get it now.
DiffRigor

DiffRigor

Preview

DiffRigor

| (0) | Free
Verify what your coding agent missed: independent production-risk review for AI-generated code changes.
Installation
Launch VS Code Quick Open (Ctrl+P), paste the following command, and press enter.
Copied to clipboard
More Info

DiffRigor

Verify what your coding agent missed.

DiffRigor is an independent production-risk verifier for Python changes after a coding agent finishes a task. It is not a general-purpose AI style reviewer. Risk Review combines deterministic changed-symbol analysis, bounded production-first investigation, concrete changed-code and caller evidence, model analysis, and deterministic evidence/consistency checks before presenting a finding.

DiffRigor 0.1 is an experimental pre-release. Findings require your judgment, and an empty result does not prove that a change is safe.

Installation

DiffRigor requires VS Code 1.85 or newer. Once the pre-release is published, find DiffRigor in Extensions and choose Install Pre-Release. To install a supplied beta package, run Extensions: Install from VSIX….

Open a trusted local Git repository with Python changes, run DiffRigor: Configure Settings, and choose a model connection.

Model configuration

Local

The default Local setup uses Ollama:

Endpoint: http://localhost:11434/v1
Model: qwen3-coder:30b

Install the default model with ollama pull qwen3-coder:30b, then start Ollama. Local accepts a complete OpenAI-compatible endpoint, so other compatible local servers can also work. DiffRigor uses the URL exactly as configured and does not append /v1.

Local describes the connection mode, not a privacy guarantee. If you change the URL to a remote address, review data is sent there. In SSH or container sessions, localhost means the machine running the VS Code extension host.

Online

Online provides OpenRouter, Kilo, and Custom OpenAI-compatible endpoint presets. OpenRouter and Kilo always use their fixed preset endpoints. Custom requires you to enter a complete http:// or https:// endpoint, which DiffRigor uses exactly as entered without appending /v1; an unconfigured Custom provider does not fall back to OpenRouter. Choose a compatible model and set its API key through the DiffRigor settings view. The key is stored in VS Code SecretStorage; the webview receives only whether a key is configured.

Each Online provider remembers its own model ID. Switching from OpenRouter to Kilo or Custom immediately restores the model last saved for that provider. OpenRouter defaults to openrouter/free; Kilo and Custom require you to enter a model instead of inheriting an OpenRouter-specific value. Existing development installs with the retired shared diffrigor.onlineModel setting migrate that explicit value only to the provider selected during the upgrade.

The saved key is bound to the effective Online endpoint. Changing to a different effective Online endpoint discards the saved key and requires setting one for the new endpoint.

Model guidance

  • Recommended local model: qwen3-coder:30b
  • Tested lower-memory option: qwen2.5-coder:7b

The 7B model has completed the Risk Review structured-output flow successfully, but it may produce less complete reasoning or findings than the recommended 30B model.

Model capability materially affects review quality. Local models provide privacy and cost advantages when they actually run locally, while stronger models may identify production risks that smaller models miss. OpenRouter and Kilo let you select compatible cloud models. Model quality and structured-output reliability vary, and DiffRigor may reject unsupported or inconsistent candidates instead of presenting them as validated findings.

How Risk Review works

For each diff, DiffRigor deterministically identifies changed Python symbols and allocates a bounded investigation set. Production files and production-file breadth are prioritized before additional production symbols and conventional test-only candidates. Documentation-only changes are skipped. Each selected symbol receives a bounded evidence bundle containing changed code and, where conservatively discoverable, direct caller context.

The selected model analyzes each investigation independently. DiffRigor then checks evidence references and consistency, rejects unsupported historical-contract, caller-usage, signature, and related claims, maps accepted findings back to reviewed source snapshots, consolidates overlapping findings, and finally applies the user's category, confidence, and maximum-finding filters. A partial review means the bounded set did not cover every changed symbol or some investigations failed; it is never presented as exhaustive repository coverage.

Untouched settings enable behavioral_regression, invariant_violation, error_handling_change, and api_contract_change. The more speculative performance_regression and coupling_increase categories remain available but off by default.

Review workflows

Command Reviewed changes
DiffRigor: Python Risk Review — Current Changes Combined tracked staged and unstaged changes; falls back to a branch comparison when the local diff is empty
DiffRigor: Python Risk Review — Staged Changes Staged changes only
DiffRigor: Python Risk Review — Branch Merge-base comparison against the detected default base

The Risk Review view also supports unstaged changes. New untracked files must be staged to appear in a Git diff. In multi-root workspaces, DiffRigor reviews the first workspace folder. Branch mode uses the first available base from origin/HEAD, origin/main, origin/master, main, or master; it does not fetch.

Open a finding to inspect its evidence, review any resulting fix, and run DiffRigor again. If a model returns malformed structured output, DiffRigor may make at most one format-repair request per investigation response, using the same selected model.

Privacy basics

  • Model requests send bounded changed code, diff context, caller evidence, and optional commit context to the configured endpoint.
  • OpenRouter, Kilo, and custom remote endpoints are external services whose policies apply. A Local connection is private only when its configured endpoint and model actually run locally.
  • File-path metadata is omitted by default. Source or commit text can still contain identifying information.
  • Likely-secret redaction is enabled by default and is best-effort, not a security guarantee.
  • Verbose debug logging is off by default. When enabled, .diffrigor/risk-review-debug.jsonl can contain prompts, code, model responses, and errors.
  • When VS Code telemetry is enabled, DiffRigor uses PostHog EU for limited Product Analytics, DiffRigor-owned error-boundary diagnostics, and narrowly scoped operational lifecycle logs. Analytics and lifecycle logs do not intentionally include source code, diffs, prompts, model responses, repository identity, or credentials. Error reports can include exception messages, path-normalized stack positions, and runtime diagnostic metadata; DiffRigor does not install process-wide exception listeners.

See the packaged PRIVACY.md for details.

Limitations

Risk Review is Python-focused, bounded, and heuristic. Its changed-symbol and conservative textual caller analysis can produce partial coverage. It does not semantically resolve every import or alias, build a repository-wide dependency graph, follow arbitrary multi-hop dependencies, or guarantee exhaustive findings.

DiffRigor does not read coding-agent sessions or original tasks, detect AI authorship, know which tests were run, verify task completeness, or replace human review and testing.

Support

After publication, report installation problems, crashes, false positives, and missed risks through the DiffRigor Marketplace listing's Q&A. Use a minimal synthetic example; do not post proprietary code, API keys, repository identifiers, or raw verbose logs. See the packaged SUPPORT.md.

License

DiffRigor is proprietary software. DiffRigor 0.1 is available at no charge for personal and internal commercial software-development use. See the packaged LICENSE.txt for the complete terms and THIRD_PARTY_NOTICES.txt for bundled components.

  • Contact us
  • Jobs
  • Privacy
  • Manage cookies
  • Terms of use
  • Trademarks
  • Your Privacy Choices
  • Consumer Health Privacy
© 2026 Microsoft