- Edge Cases & Boundary Conditions: Rigorous checks on null/undefined safety, empty inputs, unhandled promise rejections, and fallback behavior.
- Broken, Phantom, or Missing Imports: Cross-references imported symbols against AST module graphs to flag runtime
TypeErrorissues before merge. - Security & Trust Boundaries: Analyzes authentication/authorization gates, credential leaks, unvalidated inputs, and injection vectors.
- Architectural & System Design Trade-offs: Evaluates coupling, memory footprint, concurrency/race conditions, and project-specific idioms.
- 1-Click GitHub Suggestions: Produces exact, indented code replacement blocks directly executable via GitHub’s “Apply suggestion” button.
How the PR Review Pipeline Works
When a developer opens or updates a Pull Request in a connected repository, Blame processes the event in real-time:1. Webhook Ingestion & Smart Diff Filtering
Blame intercepts GitHubpull_request and synchronize webhooks. Before initiating AI evaluation:
- Noise & Asset Stripping: Automatically filters out lockfiles (
package-lock.json,pnpm-lock.yaml,Cargo.lock), minified bundles, build outputs, and binaries. - Diff Line Annotation: Uses
parse-diffto attach precise line numbers (+added,-deleted, unchanged context) ensuring every comment anchors to real diff coordinates. - Scale Boundaries: Analyzes up to 50 modified files and 4,000 diff lines per pull request to optimize review depth without degrading context quality.
2. Multi-Source Context Gathering
Blame surrounds the pull request diff with three layers of intelligence:A. Auto-Discovered Project Rules & Instruction Files
Blame scans the repository root and subdirectories to load team guidelines and coding conventions. It natively detects:.cursorrulesand.cursor/rules/*.mdc(including glob-scoped rules)CLAUDE.mdand.claude/CLAUDE.mdAGENTS.mdand.agents/AGENTS.mdblame.yaml/.blamerc/.coderabbit.yaml.github/copilot-instructions.mdCONTRIBUTING.mdanddocs/architecture.md
B. Repository Memory & Custom Team Guidelines
Rules configured in the Blame dashboard under Repository Settings > Memory are dynamically injected to enforce team-specific patterns.C. GraphRAG Cross-File Analysis
Blame queries the repository’s Tree-sitter AST index and runs Voyage AIrerank-3 to retrieve upstream imports and downstream callers affected by the diff.
3. Calibrated Confidence Scoring (1 to 5)
Every pull request review receives a calibrated confidence rating with a detailed rationale:4. Structured Output & Inline Comments
Blame posts two types of feedback on GitHub:Executive PR Summary
A top-level comment structured with clear sections:- Executive Overview: High-level problem statement and core impact.
- Architectural & Design Evaluation: Assessment of coupling, modularity, and trade-offs.
- Edge Cases & Boundary Analysis: Defensive invariants and runtime pitfalls.
- Security & Reliability Audit: Scrutiny of data validation and failure isolation.
- Recommended Test Coverage: Concrete unit/integration test cases needed for full confidence.
Actionable Inline Comments
Every detected issue is anchored to its specific line and tagged with:- Severity:
Critical,High,Medium, orLow. - Category:
Bug,Security,Performance,Architecture,Maintainability,Testing, orReadability. - 1-Click Suggestion: Pre-formatted diff replacements matching exact file indentation so developers can accept fixes with one click.
Triggering Reviews
Reviews can be triggered in three ways:- Automatic (On PR Open / Sync): Whenever a PR is opened or new commits are pushed (configurable in Repo Settings).
- Slash Command: Comment
/blame reviewor/reviewdirectly on any GitHub PR. - Manual Trigger: Click Trigger Review inside the Blame web dashboard.
Related Guides
- Graph-Based Codebase Context — How Blame indexes code and queries symbol graphs.
- Repository Settings — Configuring review triggers, automated comments, and file ignore rules.
- Chat & Codebase Memory — Interactive multi-repo chats and workspace memory.