đ° New: Triage â a self-updating cross-repository queue that prioritizes pull requests by value and risk, so you always know what to review next. Explore Triage â
Complete reference for all CodeRabbit supported tools and their configuration options.
This reference is generated automatically. Last updated: October 6, 2026
CodeRabbit supports integration with 59 static analysis tools, linters, and security scanners. You can configure each tool individually via the web interface or your .coderabbit.yaml file, see the configuration overview for details.
Blinter is a linter for Windows batch files that provides comprehensive static analysis to identify syntax errors, security vulnerabilities, performance issues, and style problems.Version: v1.1.27
ember-template-lint is a linter for Handlebars template files that checks for common issues such as accessibility violations, deprecated patterns, and template anti-patterns.Version: v7.9.3
Optional path to an ESLint configuration file relative to the repository. When set, this configuration is used for every file instead of discovering ESLint configurations recursively.
Optional path to the golangci-lint configuration file relative to the repository. Useful when the configuration file is named differently than the default â.golangci.ymlâ, â.golangci.yamlâ, â.golangci.tomlâ, â.golangci.jsonâ.
Run only the rules and categories listed in enabled_rules or enabled_categories, instead of the default set.Defaults to false.With enabled_only: true, at least one rule or category is required. If both lists are empty, CodeRabbit skips LanguageTool and reports an error.
If set to âpickyâ, additional rules will be activated, i.e. rules that you might only find useful when checking formal text.One of: default, pickyDefaults to "default".
Enable OpenGrep: OpenGrep is a high-performance static code analysis engine for finding security vulnerabilities and bugs across 17+ languages.Defaults to true.
Example configuration:
.coderabbit.yaml
reviews: tools: opengrep: enabled: true
OSV Scanner
OSV Scanner is a tool for vulnerability package scanning.Version: v2.6.0
Level: Specify the rule level to run. When set to default, the level is determined by the review profile: chill uses level 3 (real bugs only â return/property type mismatches, array offset errors) and assertive uses level 8 (adds dead code detection, argument type checking, null safety, and typehint checks). This setting is ignored if your configuration file already has a level: parameter.One of: 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, default, maxDefaults to "default".
Microsoft Presidio Analyzer 2.2.364 detects sensitive identifiers (including payment cards, US SSN, cryptocurrency wallets, and phone numbers) in changed files. Tune entities, thresholds, and languages in repository Presidio configuration (for example .presidiocli or AnalyzerEngineProvider YAML); the built-in scan uses fixed defaults and is skipped when that configuration is present.Version: v2.2.364
Optional path to a Ruff configuration file relative to the repository. When set, this configuration is used for every reviewed file instead of Ruffâs closest-config discovery.
Enable SkillSpector: SkillSpector is a security scanner for AI agent skills. It detects vulnerabilities, malicious patterns, and security risks in SKILL.md manifests and MCP configurations.Defaults to true.
Example configuration:
.coderabbit.yaml
reviews: tools: skillspector: enabled: true
Smarty Lint
smarty-lint is a linter for Smarty 3 template files that checks for common issues such as incorrect operator usage, naming conventions, empty blocks, and unquoted strings.Version: v0.3.3
Optional path to the SQLFluff configuration file relative to the repository. Use this when the config file is not named one of SQLFluffâs default filenames.
Optional path to the SwiftLint configuration file relative to the repository. This is useful when the configuration file is named differently than the default â.swiftlint.ymlâ or â.swiftlint.yamlâ.
Enable Vale: Vale checks prose against repository-defined editorial style rules. It runs only when a supported root Vale configuration is present.Defaults to true.
Example configuration:
.coderabbit.yaml
reviews: tools: vale: enabled: true
Verilator
Verilator statically analyzes Verilog and SystemVerilog source files.Version: v5.052