{"slug": "review-code-without-reading-diffs", "title": "Review code without reading diffs", "summary": "Ghvstcode released grsp, a macOS app that uses a user's existing Claude Code or Codex subscription to explain what a pull request changes rather than which lines moved, verifying every agent-reported file:line reference against a read-only git worktree. In its latest eval run across four fixture PRs in Python, TypeScript, Go and YAML/SQL, grsp verified 280 code references and dropped 0. The app requires no API keys, leaves the user's working copy untouched, and posts AI-assisted reviews to GitHub as normal reviews.", "body_md": "**grsp is a macOS app that shows you what a pull request does, not just which lines moved.**\n\n  It runs on the Claude Code or Codex subscription you already have. No API keys.\n\n[Website](https://grsp.app)  · \n  [Docs](https://grsp.app/docs)  · \n  [Changelog](https://grsp.app/changelog)  · \n  [Build from source](#build-from-source)\n\nA diff tells you which lines changed. It doesn't tell you what the system does differently now, which paths the author forgot, or whether the description is still true.\n\nPoint grsp at a pull request and your own coding agent reads the change in a read-only worktree. Then grsp checks every claim the agent makes against git before any of it reaches your screen. You get the behaviour, with the code beside it as proof.\n\nWhat the author says, next to what the code does. If they disagree, that is the first thing you see.\n\nBelow that: every entry point whose behaviour changes, the ones the PR should have touched and didn't, questions to test your understanding, the GitHub discussion, and an Ask panel that answers with code excerpts and `file:line` references.\n\nStep through the changed behaviour block by block, from the entry point to the database write. Try \"what if\" inputs to see which path they take.\n\nRun an AI review with your own prompt. Edit the findings, choose which to include, pick a verdict and post it to GitHub as a normal review.\n\n<sub>Screenshots are the app running on its built-in fixture scenario. You can open the same screens yourself with [fixture mode](#build-from-source).</sub>\n\n1. **Point it at a PR.** Paste a GitHub PR link, pick from a repo's open PRs, or choose two branches. If you don't have the repo locally, grsp offers to clone it.\n2. **Your agent explores.** grsp fetches the refs, checks out a detached worktree at the PR head and runs Claude Code or Codex against it in read-only mode.\n3. **grsp verifies.** Every`file:line` the agent returns is matched against the worktree. A reference that is a few lines off is snapped to the right line; one that can't be found is dropped.\n4. **You read the result.** Each section appears as soon as it is ready, and tells you how much was explored, verified and left unverified.\n\nThe whole design follows one rule:\n\n**The agent discovers and interprets. git and the worktree confirm.**\n\nChange status, line numbers, code excerpts, comment threads and CI never come from agent output.\n\n- **It can't show you code that isn't there.** Locations are verified, excerpts are read from disk, and New / Changed / Unchanged is computed from the diff, never taken from the model. Mismatches and findings with no verified reference are not shown.\n- **It finds what the PR left out.** The most useful thing in a review is often the code path nobody touched. grsp lists those as \"Not covered\".\n- **Any language.** There is no parser and no list of supported frameworks. If your agent can read the code, grsp can verify what it says about it.\n- **No API keys.** grsp shells out to the`claude` or`codex` CLI you are already signed in to. It never asks for, uses or stores a model key.\n- **It doesn't touch your working copy.** The worktree lives in grsp's own data folder. Your branches and uncommitted work stay as they are.\n- **It spends your subscription carefully.** Results are cached by head commit, walkthroughs run when you open them, and nothing re-runs unless you ask.\n\nThe eval suite runs the real pipelines against four fixture PRs in Python, TypeScript, Go and YAML/SQL. On the latest run with Claude Code, 280 code references were verified and 0 were dropped. Run it yourself with `pnpm eval`.\n\n1. Download grsp for [Apple silicon](https://github.com/Ghvstcode/grsp/releases/latest/download/grsp_aarch64.dmg) or[Intel](https://github.com/Ghvstcode/grsp/releases/latest/download/grsp_x64.dmg) , open the`.dmg` and drag grsp into Applications.\n2. Make sure you have [Claude Code](https://docs.anthropic.com/en/docs/claude-code) or[Codex](https://developers.openai.com/codex/cli) installed and signed in. One is enough.\n3. For pull requests, install the [GitHub CLI](https://cli.github.com) and run`gh auth login` . Without it you can still compare two branches.\n4. Open grsp. Onboarding finds your agent, checks GitHub and asks for a repo folder. Then paste a PR link.\n\nThe [Getting Started guide](https://grsp.app/docs#getting-started) covers each step in more detail.\n\nYou need macOS, Node.js 22 or newer, pnpm and stable Rust.\n\n```\ngit clone https://github.com/Ghvstcode/grsp.git\ncd grsp\npnpm install\npnpm tauri:dev\n```\n\nNo agent or GitHub account to hand? Fixture mode renders every screen from a built-in scenario:\n\n```\nVITE_GRSP_FIXTURES=1 pnpm tauri:dev    # in the app\nVITE_GRSP_FIXTURES=1 pnpm vite:dev     # in a browser, at localhost:1420\n```\n\nChecks and tests:\n\n```\npnpm validate    # lint, format check and typecheck\npnpm test        # frontend tests (Vitest)\ncargo test --manifest-path src-tauri/Cargo.toml    # Rust unit and contract tests\npnpm eval        # run the real pipelines on the fixture PRs and score them\n```\n\n`pnpm eval` uses your own agent subscription, so it is local and on demand, never part of CI. See [evals/README.md](https://github.com/Ghvstcode/grsp/blob/main/evals/README.md).\n\ngrsp is built with [Tauri 2](https://v2.tauri.app), React and Rust. The Rust core has five modules: `git`, `verify`, `agent`, `pipelines` and `github`. Every pipeline is the same shape: build the prompt, run the agent, parse, verify, persist. [docs/architecture.md](https://github.com/Ghvstcode/grsp/blob/main/docs/architecture.md) has the full picture.\n\n- **Your code stays on your Mac.** It is read from a local worktree, and the only place it goes is your own Claude Code or Codex, under the terms you already have with that provider. The agent runs read-only.\n- **Nothing is posted until you press Post.** GitHub is reached through`gh` with your account. Analyses and history live in a SQLite database on your disk.\n- **Usage metrics are anonymous and optional.** grsp's server handles sign-in and records which features are used and whether analyses finish. It never receives repository names, code, diffs, PR titles, questions, comments or agent output. Turn metrics off in Settings → General.\n\nMore in the [privacy section of the docs](https://grsp.app/docs#privacy).\n\n**Can the agent be wrong?**\nYes. It can misread code like any reviewer. What it can't do is show you a location that doesn't exist or call unchanged code changed. Treat its notes as a well-read colleague's explanation, and the code beside them as the fact.\n\n**How much of my subscription does a review use?**\nA handful of agent passes per PR. The session footer shows the count, and nothing runs in the background.\n\n**Can I use it without GitHub?**\nYes. Choose two branches as base and head. You get the Gist, Ask, walkthroughs and the AI review. There is no discussion and no posting.\n\n**Does it work on Windows or Linux?**\nNot today. grsp is a macOS app.\n\nMore answers in the [docs FAQ](https://grsp.app/docs#faq).\n\nIssues and pull requests are welcome. [CONTRIBUTING.md](https://github.com/Ghvstcode/grsp/blob/main/CONTRIBUTING.md) has the setup, the conventions and the one rule every change has to respect.", "url": "https://wpnews.pro/news/review-code-without-reading-diffs", "canonical_source": "https://github.com/Ghvstcode/grsp", "published_at": "2026-10-06 19:23:33+00:00", "updated_at": "2026-10-06 19:49:51.584300+00:00", "lang": "en", "topics": ["ai-agents", "developer-tools", "ai-tools", "artificial-intelligence"], "entities": ["grsp", "Ghvstcode", "Claude Code", "Codex", "Anthropic", "OpenAI", "GitHub", "macOS"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/review-code-without-reading-diffs", "markdown": "https://wpnews.pro/news/review-code-without-reading-diffs.md", "text": "https://wpnews.pro/news/review-code-without-reading-diffs.txt", "jsonld": "https://wpnews.pro/news/review-code-without-reading-diffs.jsonld"}}