LWBRUT Logo

LWBRUT

Code Intelligence & PR Verification
Anthropic Claude 3.5 Sonnet Integration
Model Context Protocol (MCP) Ready

Deterministic AST verification meets Claude-driven code reasoning.

LWBRUT parses abstract syntax trees and executes deep multi-file contextual analysis via Claude 3.5 Sonnet to catch race conditions, logic errors, and security holes before your PR merges.

Inspect Architecture
github.com/org/payment-service โ€” PR #142 (lwbrut-verify) โ— verified
44func (s *OrderSession) CommitOrder(ctx context.Context, orderID string) error {
45 s.mu.Lock()
46- // Missing defer unlock leads to deadlocks when tx.Commit fails
47- if err := s.tx.Commit(ctx); err != nil { return err }
48+ defer s.mu.Unlock()
49+ if err := s.tx.Commit(ctx); err != nil { return fmt.Errorf("commit failed: %w", err) }
โšก lwbrut-bot[bot] High Severity
via Claude 3.5 Sonnet AST Analysis
Deadlock Vulnerability Detected: On error path at line 47, s.mu mutex remained locked because unlock occurred only at function exit. In a distributed worker, this halts queue consumption for the key.
AST Verify: Synthesized patch validated against Go 1.23 sync semantics. Verified zero side-effects on OrderSession call sites.
50 return s.metrics.RecordSuccess(orderID)
51}
Engine Capabilities

Built for production codebases that cannot afford regressions.

Traditional linters flag style syntax. LWBRUT reasons about runtime state, concurrency, and security blast radius.

๐Ÿ”

Cross-File Call Graph Awareness

LWBRUT does not review diffs in isolation. It parses imports, type definitions, and call chains across your entire repository to verify that breaking changes do not break downstream handlers.

๐Ÿ›ก๏ธ

Zero-Hallucination AST Grounding

Every review comment generated by Claude 3.5 Sonnet passes through Tree-sitter abstract syntax tree verification. If a recommended variable, method, or package does not exist, the comment is discarded.

โšก

Model Context Protocol (MCP) Native

Run LWBRUT in cloud CI/CD or locally on your machine. Connect via stdio or SSE to Claude Code, Cursor, and custom agentic workflows to get instant local diff feedback.

๐Ÿ”’

OWASP & Logic Vulnerability Triage

Detect subtle authorization bypasses, race conditions, unsanitized inputs, and leaked credentials. Flags vulnerabilities before security scans block your release train.

๐Ÿงช

Deterministic Test Generation

When code introduces uncovered branches, LWBRUT suggests runnable unit tests tailored to your testing framework (pytest, Go test, Vitest, cargo test) matching repository conventions.

๐Ÿ“Š

Customizable Enforcement Policies

Define rules as declarative markdown or YAML specs. Block merges only on critical logic hazards while keeping stylistic suggestions non-blocking.

Technical Architecture

How LWBRUT verifies code without hallucinations.

A hybrid pipeline combining deterministic static parsing with high-intelligence LLM reasoning.

STEP 01

Git Webhook Ingestion

Captures Pull Request payloads from GitHub or GitLab. Computes base ref vs head ref delta and identifies modified symbols.

STEP 02

AST & Graph Extraction

Tree-sitter builds syntax trees and call graphs. Extracts context headers, signatures, and surrounding implementation logic.

STEP 03

Claude 3.5 Sonnet Reasoning

Anthropic Claude evaluates the semantics, execution flow, race hazards, and edge cases with 200K token multi-file context.

STEP 04

Compiler / AST Verification

Linter validation ensures the suggested patch parses cleanly. Comments are posted with exact line anchors on GitHub.

Comparison Matrix

Why generic linters and naive LLM wrappers fail.

Engineering teams reject noisy bots. LWBRUT is designed for signal-over-noise.

Evaluation Dimension Standard Linters (ESLint, Go Vet) Naive LLM PR Bots LWBRUT (Claude + AST)
Context Scope Single file, syntax only Diff hunks only (misses dependencies) Full repo call graph & symbol context
False Positive Rate Low (rigid rules) High (hallucinates APIs & imaginary bugs) Under 3% (AST verified before posting)
Concurrency & Logic Flaws Cannot detect Inconsistent guesses Deterministic detection via Claude reasoning
Execution Protocol CLI only Proprietary webhook GitHub App + Model Context Protocol (MCP)
Security & Data Policy Local execution Vague data retention Zero data retention on Anthropic commercial API
ANTHROPIC MCP PROTOCOL

Run LWBRUT Locally in Claude Desktop

Connect LWBRUT's deterministic AST intelligence server directly to your local Claude Desktop app using Model Context Protocol (MCP).

View GitHub Organization โ†—
// claude_desktop_config.json
{
  "mcpServers": {
    "lwbrut": {
      "command": "npx",
      "args": ["-y", "@lwbrut/mcp-server@latest"]
    }
  }
}
Transparent Pricing

Simple plans for teams of every scale.

Start free on open-source repositories or self-host via Model Context Protocol.

Developer

For individual engineers and open source maintainers.

$0 / forever
  • โœ“ Up to 5 public repositories
  • โœ“ Standard PR reviews (Haiku / Sonnet)
  • โœ“ Model Context Protocol local runner
  • โœ“ Community support

Enterprise

For organizations with strict compliance & VPC needs.

Custom
  • โœ“ Self-hosted on AWS / GCP / Azure VPC
  • โœ“ Custom fine-tuned rule enforcement
  • โœ“ SSO (SAML / Okta) & audit logging
  • โœ“ Dedicated solutions architect
  • โœ“ Custom BAA / DPA contractual terms
Frequently Asked Questions

Clear answers to technical questions.

Does LWBRUT or Anthropic train on our private code?
No. We use Anthropic's commercial API tier with zero-day data retention policies for model training. Your code is processed in transient volatile memory solely during the lifecycle of the PR review run and is never cached or used to train public or proprietary models.
How does LWBRUT eliminate false positives?
Before posting any comment on GitHub, LWBRUT runs an AST verification gate using Tree-sitter. If the suggested code references methods, variables, or types that do not resolve within your codebase or standard libraries, the suggestion is suppressed.
What programming languages are supported?
LWBRUT provides full AST cross-file parsing for TypeScript, JavaScript, Python, Go, Rust, Java, C++, and PHP. Additional languages are supported via multi-file context analysis.
How does it integrate with existing CI/CD?
You can install the official GitHub App in under 60 seconds, run it via GitHub Actions workflow YAML, or execute it locally inside your terminal using the Model Context Protocol (MCP) server integration.
Can we configure custom rules and guidelines?
Yes. You can add a .lwbrut/rules.md file in your repository root to declare custom engineering standards, required patterns, and specific guidelines your team follows.

Ready to eliminate logic regressions?

Join engineering teams shipping safer code with automated Claude 3.5 Sonnet reviews.

โœ“ Notification message