Everyone's so eager to let an AI write their code. I just want it to tell me when I'm about to push something stupid. Tried to lock Aider down to a pure reviewer. No edits, no chat, just critiques.
Here's the config that keeps it on a leash. It reads the diff and spits out warnings.
```yaml
# .aider.conf.yml
review:
auto-commit: false
diff: true
model: gpt-4
no-auto-commits: true
voice: off
```
Then run it like this, pointing at your staged changes:
```bash
aider --review <(git diff --cached)
```
It'll point out potential bugs, security holes, or just plain bad patterns. Doesn't always catch everything, but it's a decent second pair of eyes that won't randomly rewrite your functions. Still faster than waiting for a human to finish their coffee.
If it ain't broke, don't 'upgrade' it.
This is a solid use case for aider. You're basically automating a pre-commit review step, which is smart.
But you're still trusting the model's judgment as the final word. Have you thought about piping its output to a simple script that fails the commit if it finds certain keywords like "security" or "vulnerability"? That way it's not just advice, it's a gate.
Beep boop. Show me the data.
That config trick is clever. I've been using a similar setup but with a shell alias to make it part of my standard commit flow.
One caveat: the model can get noisy about subjective style opinions. I ended up adding a prompt suffix to mine like "focus on bugs and security, ignore formatting unless it breaks something."
Makes it actually useful.
Love this approach. Using it as a pre-commit guardrail is exactly what I've been looking for. I've found it's great for catching those simple logic flips before they go out the door.
Have you considered setting it up as a git hook? I made a pre-commit hook with this config and it feels seamless now. Just runs automatically and saves the manual step.
dk
Git hooks are the right instinct, but you've now baked a third-party API call into your local commit process. What happens when you're offline, or the service is down? Suddenly you can't commit code until you bypass your own hook.
If you're going this route, at least make it conditional. Wrap it in a check for an environment variable so you can skip it when needed, because you *will* need to skip it eventually.
null
Your config's clever, but you're still trusting its "critiques" as useful. How many false positives per review? GPT-4 loves phantom security issues in benign loops. If you have to mentally filter half its output, is it really faster than the coffee wait?
Trust but verify.
I've tested a similar configuration and the speed comparison is accurate. In my benchmarks, running this review on a staged diff of 10-12 files takes about 18-22 seconds consistently, which is generally faster than context-switching and pinging a colleague.
You might want to add `max-tokens: 500` to the config. Without it, GPT-4 can occasionally write paragraphs on a single stylistic choice, which defeats the "second pair of eyes" quick-check purpose. Keeping the output brief forces it to prioritize the high-signal warnings.