1. The Core Bottleneck: What Engineering Flaw Does It Fix?
Mainstream AI coding assistants face catastrophic token overheads when performing code reviews on medium-to-large codebases. Every minor change often triggers the AI tool to re-read tens of thousands of lines of raw corpus. This indiscriminate scanning inflates inference latency and balloons cloud API bills. code-review-graph establishes a structural code knowledge graph locally, forcing the AI assistant to read only the minimal code slices affected by a change.
💡 Core Architectural Insight: By translating unstructured text into a local relational graph via Tree-sitter, the project reduces global text retrieval to local graph traversal along strict call boundaries.
2. Core Architecture and Data Flow Analysis
code-review-graph relies on a local SQLite store for ASTs and entity relationships extracted from the source tree. The pipeline begins with static analysis via Tree-sitter to extract functions, classes, and imports, persisting them as nodes and edges. When a review is triggered, the MCP server calculates the blast radius based on file diffs, retrieving direct callers, dependents, and tests to assemble a high-precision context slice.
[ Codebase / Git ] ---> [ Tree-sitter Parser ] ---> [ SQLite Graph Store ]
│
▼
[ AI Assistant (MCP) ] <--- [ Minimal Review Set ] <--- [ Blast Radius Engine ]
The blast radius analysis module drives the architecture. When a low-level function undergoes a SHA-256 hash change, the graph traverses incoming call and import edges to pinpoint downstream impacts. The incremental update engine re-parses only modified files, keeping re-index latency under 2.5 seconds for a 3,000-file repository.
3. Technology Selection and Hardcore Benchmarking
| Evaluation Dimension | This Project (code-review-graph) | Traditional Approach | Typical Competitor | Production Benefit |
|---|---|---|---|---|
| Context Acquisition | Local Tree-sitter Graph + MCP | Full File Scan / RAG Retrieval | Cloud-based Global Embedding | 65x Token Consumption Reduction |
| Update Mechanism | Git Hooks / Incremental SHA-256 | Forced Full Index Rebuild | Scheduled Bulk Vectorization | Sub-3s Incremental Update Latency |
| Privacy & Compliance | 100% Local SQLite Storage | Source Code Exposed to Vector DBs | Cloud-persisted Code Snippets | Zero Internal Code Leakage Risk |
| Editor Ecosystem | Native Support for 16 AI Tools | Single Editor Plugin Binding | Requires Standalone Client Setup | Zero Friction Workflow Integration |
Data confirms that local graph routing outperforms vector RAG in token efficiency and data privacy. While vector embeddings often lose precise call hierarchies, Tree-sitter graphs preserve exact function and inheritance topologies.
4. Hands-On Geek Practice: Building a Minimal Closed Loop
Configuring code-review-graph requires Python 3.10 or higher. After installing the package via your preferred package manager, use its auto-detection to register the MCP server with your editor.
# Install the CLI tool via pip
pip install code-review-graph
# Detect installed AI coding tools and configure MCP entries
code-review-graph install --platform cursor
# Parse and build the initial graph for the workspace
code-review-graph build
Once installed, open the repository in Cursor or Claude Code and invoke the graph context with a prompt:
Build the code review graph for this project
The CLI outputs build status metrics upon completion. If any file fails to parse, the result returns a partial status with warnings printed to stderr, retaining previous graph rows for unaffected files to maintain stability.
5. Production Gotchas and Pitfalls
Initial cold starts on mixed-language, large-scale repositories consume substantial CPU cycles. Because Tree-sitter performs lexical and syntactic analysis on every source file, a cold build of 3,000 files takes roughly 40 seconds on a single thread.
⚠️ Gotcha Warning [Cold Start Latency]: Avoid running an initial
builddirectly inside CI pipelines or low-spec virtual machines on monorepos. Pre-generate the SQLite database locally and ignore it in Git or mount it via shared caches.⚠️ Gotcha Warning [Incremental Desync]: If external scripts batch-modify file permissions or move massive directory trees, Git hooks may fail to capture correct SHA-256 state transitions. Run
code-review-graph build --forcemanually to re-sync the underlying graph.
Automated uninstallation and cleanup in CI environments require careful handling. Using the code-review-graph uninstall --keep-data flag removes editor integration hooks while preserving the graph database, preventing costly rebuild overhead.
