Run AI Agents in CI/CD Pipelines: GitHub Actions & TypeScript Guide
Run AI Agents in CI/CD Pipelines: GitHub Actions & TypeScript Guide: Designed as a zero-dependency, open-source TypeScript architecture under the MIT License with native Model Context Protocol (MCP) support and deterministic phase state machines.
- Catch bugs and code smells on every PR before human review
- Auto-generate missing unit tests on changed files
- Enforce architectural rules with agent-powered linting
- Post structured review comments directly to GitHub PRs
name: AI Code Reviewon:pull_request:types: [opened, synchronize]jobs:ai-review:runs-on: ubuntu-lateststeps:- uses: actions/checkout@v4with:fetch-depth: 0- uses: actions/setup-node@v4with:node-version: '20'- run: npm install smoke-monkey-harness- name: Run AI Code Reviewenv:ANTHROPIC_API_KEY: ${{ secrets.ANTHROPIC_API_KEY }}GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}run: node ./.github/scripts/ai-review.ts
Why Run AI Agents in CI/CD?
Traditional CI pipelines run deterministic linters and test suites. AI agents add a reasoning layer that can:
- Understand intent, not just syntax — detecting logical bugs that static analysis misses.
- Generate context-aware tests for new code paths without manual effort.
- Refactor safely by understanding the full codebase, not just the changed diff.
- Document automatically by reading the change and updating JSDoc or README sections.
Setting Up the Review Script
Create '.github/scripts/ai-review.ts' in your repository. This script uses the GitHub API to fetch the PR diff, passes it to Smoke Monkey, and posts review comments back.
Use autoApprove: true in CI
Always set autoApprove: true for CI runs. Human-in-the-loop permission gates are designed for interactive sessions, not unattended pipelines.
import { createAgent } from 'smoke-monkey-harness';import { execSync } from 'child_process';const diff = execSync('git diff origin/main...HEAD').toString();const prNumber = process.env.PR_NUMBER;const agent = createAgent({provider: 'anthropic',model: 'claude-3-7-sonnet',workspacePath: process.cwd(),autoApprove: true, // Non-interactive in CI});const result = await agent.run(`Review this PR diff for bugs, security issues, and missing tests.Output a JSON array of review comments with file, line, and body fields.DIFF:${diff.slice(0, 8000)}`);// Post comments to GitHub via APIconsole.log('Review complete:', result);
Keeping API Keys Safe in GitHub Actions
Store your LLM API key as a GitHub Actions secret:
- Go to Settings → Secrets and variables → Actions in your repository.
- Click New repository secret.
- Name it
ANTHROPIC_API_KEY(orOPENAI_API_KEY/GEMINI_API_KEY). - Reference it in your workflow with
${{ secrets.ANTHROPIC_API_KEY }}.
Smoke Monkey reads the key from the environment variable automatically when you set the provider.
Frequently Asked Questions
Q:How do I prevent the agent from making unintended file changes in CI?
Set autoApprove: true but restrict the workspacePath to a read-only checkout, or run the agent in a sandboxed Docker container with no write permissions outside the analysis output directory.
Q:Can I use Smoke Monkey in GitLab CI or Jenkins?
Yes. Any CI system that can run Node.js 18+ can execute Smoke Monkey. Set the LLM API key as a CI/CD variable and run your agent script as a normal pipeline step.
Related Alternatives & Comparisons
Build with Smoke Monkey Harness
Zero dependencies. 24 built-in tools. Human-in-the-loop safety. 100% open source under the MIT License.