AI Code Review for Python Projects
Python makes it easy to write something that runs and hard to see what it will do on a bad input. CodeSightAI reviews Python changes with two models, then cross-checks the findings so the list you read is short and defensible.
What the review catches in Python
- String-built SQL and shell commands, and subprocess calls with shell=True on user input.
- Unsafe deserialisation: pickle, yaml.load without a safe loader, eval on request data.
- except: and except Exception: blocks that swallow failures without context.
- Mutable default arguments and shared state across requests.
- Blocking calls inside async handlers, and missing awaits.
- Missing validation at API boundaries in Django, Flask and FastAPI handlers.
- Secrets and connection strings hardcoded in source or settings.
Framework-aware reading
A Django view, a FastAPI dependency and a Celery task fail in different ways. The review reads the surrounding file, so a finding about a missing permission check refers to the mechanism your framework actually uses.
Complements your existing checks
Keep ruff, mypy and bandit. They are fast, deterministic and good at what they cover. This review adds the reasoning pass on top — authorization, data flow and error handling — and the second model keeps it honest.
Frequently asked questions
Which Python frameworks are supported?
Any of them. Reviews are based on reading the code, so Django, Flask, FastAPI, Celery tasks and plain scripts are all analysed.
Does it run my code or my tests?
No. Nothing is executed. The review is entirely static reading of the change.
Can I review a script without connecting a repository?
Yes. Paste it into the free analyzer on the homepage.
Free plan available. No credit card required.