Back to list

Blog

Automating Code Reviews with Tactic Remote

Set up an AI-powered code review workflow that catches bugs, security issues, and quality problems before they reach your team's pull request queue.

Published Tags: Getting started / code-review / workflow / quality
Blog

Follow product and engineering updates from this channel.

Browse category

Code review is essential for software quality, but it's also time-consuming. Developers spend an estimated 6-8 hours per week reviewing colleagues' code — time that could be spent building features. AI-powered code review doesn't replace human reviewers, but it handles the mechanical aspects (catching bugs, style violations, missing error handling) so human reviewers can focus on architecture, design, and business logic.

This tutorial shows you how to set up an AI-powered code review workflow using Tactic Remote.

The Review Workflow

Here's the workflow we'll set up:

  1. A developer completes work on a feature branch.
  2. Before creating a pull request, they start a Claude Code review session from their phone.
  3. Claude Code analyzes the diff against the main branch and generates a comprehensive review.
  4. The developer addresses the findings from their phone (approving fixes or noting exceptions).
  5. The cleaned-up code is pushed and a PR is created with the AI review summary included.

This catches 60-80% of the issues that would otherwise be found during human review, dramatically reducing review cycle time.

Step 1: Prepare Your Review Prompt

Create a file called .claude-review-prompt.md in your project root. This serves as the instruction set for AI reviews:

# Code Review Instructions
 
Review all changes on the current branch compared to the `main` branch.
 
## What to Check
 
### Critical Issues (must fix before merge)
 
- **Logic errors**: Code that doesn't do what it claims
- **Security vulnerabilities**: SQL injection, XSS, auth bypasses, credential exposure
- **Data loss risks**: Missing transactions, incorrect cascade deletes, race conditions
- **Breaking changes**: API contract violations, backwards-incompatible modifications
 
### Warnings (should fix, but not blocking)
 
- **Missing error handling**: Uncaught exceptions, unhandled promise rejections
- **Performance concerns**: N+1 queries, unnecessary re-renders, missing memoization
- **Missing validation**: User input not validated before processing
- **Test coverage gaps**: New code paths without corresponding tests
 
### Suggestions (nice to have)
 
- **Readability improvements**: Unclear variable names, complex logic that could be simplified
- **Documentation gaps**: Public APIs without JSDoc/TSDoc comments
- **Potential refactoring**: Duplicated logic, overly long functions
 
## Output Format
 
For each finding, provide:
 
1. **Severity**: CRITICAL / WARNING / SUGGESTION
2. **File**: Exact file path and line numbers
3. **Description**: What the issue is, in one sentence
4. **Explanation**: Why it matters, with context
5. **Fix**: Concrete code suggestion to resolve the issue
 
At the end, provide:
 
- Summary: X critical, Y warnings, Z suggestions
- Overall assessment: Is this branch ready for human review?
 
## What NOT to Flag
 
- Style preferences covered by our linter (ESLint/Prettier handle this)
- Import ordering (automated)
- Whitespace or formatting (automated)
- Type annotations that TypeScript can infer

This prompt is deliberately specific. Vague review instructions produce vague reviews. Specific instructions produce actionable findings.

Step 2: Run the Review from Your Phone

When you're ready to review a branch, open Tactic Remote and start a session pointed at the project directory. Send:

Checkout branch feature/user-dashboard.
Follow the review instructions in .claude-review-prompt.md.

Claude Code will:

  1. Checkout the branch
  2. Compute the diff against main
  3. Analyze every changed file according to your review criteria
  4. Output a structured review report

This typically takes 3-8 minutes depending on the size of the diff. You'll get a notification when it's complete.

Step 3: Review the Findings

The review output appears in your terminal view. Here's what a typical finding looks like:

🔴 CRITICAL — src/api/routes/users.ts:47-52

Description: SQL query constructed with string concatenation, vulnerable to injection.

Explanation: The search query parameter is interpolated directly into the SQL
string without parameterization. An attacker could craft a search input that
modifies the query logic, potentially extracting or modifying data.

Fix: Use parameterized query:
  // Before (vulnerable)
  const results = db.query(`SELECT * FROM users WHERE name LIKE '%${search}%'`)

  // After (safe)
  const results = db.query('SELECT * FROM users WHERE name LIKE ?', [`%${search}%`])

For each finding, you have three options from your phone:

Apply the fix: Prompt Claude Code to implement the suggested fix:

Apply the fix for the SQL injection issue in users.ts:47.

Skip: If you disagree with the finding or it's a false positive, note it for later and move on.

Discuss: If you're unsure, ask Claude Code for more context:

Explain the SQL injection risk in more detail. Is this exploitable given
our authentication middleware that runs before this route?

Step 4: Automated Fix Application

For reviews with many findings, you can batch-apply fixes:

Apply fixes for all CRITICAL and WARNING findings from the review.
For each fix, run the relevant tests to verify the fix doesn't break anything.
Report which fixes were applied and which tests passed.

Claude Code will work through the findings systematically, applying fixes and running tests. This is another task where you can put your phone down and wait for the notification.

Important: Review the applied fixes before committing. AI-generated fixes are usually correct, but "usually" isn't good enough for production code. Use the terminal view to check the diff:

Show me the complete git diff of all changes made during this review.

Step 5: Generate the PR Summary

Once fixes are applied and verified, generate a PR-ready summary:

Create a pull request description that includes:
1. What this branch does (based on the commit history)
2. Summary of the AI review findings and how they were addressed
3. Any remaining suggestions that were intentionally deferred
4. Test results

Include this in your PR description. It gives human reviewers confidence that the code has been pre-reviewed and tells them what to focus on.

Advanced: Continuous Review Sessions

For long-running feature branches, run reviews regularly rather than only at PR time:

Review all commits since the last review marker.
After completing the review, create a git tag 'last-ai-review' at HEAD.

By running reviews daily, you catch issues closer to when they were introduced. This is easier to fix than discovering problems after a week of development.

Integration with CI/CD

For teams that want to formalize AI review, you can trigger a review session automatically when a branch is pushed. The workflow:

  1. CI webhook triggers the Tactic Remote Mac companion app.
  2. Companion app starts a Claude Code session on the updated branch.
  3. Claude Code runs the review prompt.
  4. Results are posted as a comment on the pull request.

This requires scripting on the Mac side (the companion app exposes an API for session management) and is detailed in our advanced integration documentation.

Measuring Impact

After adopting AI code review, track these metrics:

  • Time in review: Should decrease by 30-50% as human reviewers spend less time on mechanical checks.
  • Issues caught in review vs. production: Should shift left — more issues caught during AI review, fewer escaping to production.
  • Review cycle time: The time from PR creation to approval should decrease as PRs arrive pre-reviewed.
  • Developer satisfaction: Reviewers should report less tedium and more focus on meaningful architectural feedback.

AI code review is not about replacing human judgment. It's about ensuring human judgment is spent on the problems that matter most — architecture, design, and business logic — rather than catching typos and missing null checks.

Start with a single project, refine your review prompt based on results, and expand to the team once you've calibrated the approach. The investment in a good review prompt pays dividends across every review that uses it.

Try Tactic Remote

Control your coding Agents from your phone

Connect to Claude Code, Codex, and other Agents on your Mac, Windows, or Linux computer. Check progress and send the next instruction from iPhone or iPad.