Aptu
Aptu is an AI SDLC review harness for GitHub (GitHub App, CLI, and GitHub Action) that assembles structured context before every AI call, so review quality does not depend on which surface you use.
GitHub App
Install the Aptu GitHub App to enable AI-powered issue triage and PR review across your repositories with zero workflow changes.
Grant the app access to a repository, then commit a .github/aptu.yml file to opt in:
version: 1
triage:
enabled: true
review:
enabled: true
paths:
- "src/**"
- "crates/**"
- "!**/*.md"
ai:
provider: openrouter
model: google/gemma-4-26b-a4b-it
api-key-secret: OPENROUTER_API_KEY
All installations must supply an ai block with provider, model, and api-key-secret. api-key-secret is the name of a repository secret containing the API key.
Mention commands: Comment @aptu triage on an issue or @aptu review on a PR to trigger the app manually. The app responds with a reaction to confirm receipt.
Automatic security scanning: When scan.enabled: true is set in .github/aptu.yml, the app runs aptu scan-security on every PR push event, uploads SARIF results to GitHub Code Scanning, and posts a commit status. Scanning is local pattern matching only and does not require an ai block. See docs/SECURITY_SCANNING.md.
Quotas: The app enforces per-installation and global rate limits. When a quota is exceeded, the webhook returns 429 Too Many Requests with a Retry-After header.
See docs/GITHUB_ACTION.md for the full configuration schema.
Features
| Feature | App | CLI | Action |
|---|---|---|---|
Config-as-code (.github/aptu.yml) |
Yes | - | - |
| AI Triage | Yes | Yes | Yes |
| PR Analysis | Yes | Yes | Yes |
| Dependency Enrichment | Yes | Yes | Yes |
| Multiple Providers | Yes | Yes | Yes |
| OpenSSF Best Practices Silver | Yes | Yes | Yes |
| Structural Graph Context | - | Yes | Yes |
| Prompt Customization | Yes | Yes | - |
| Observability | - | Yes | Yes |
| Model-Tier Routing | - | Yes | Yes |
| Issue Discovery | - | Yes | - |
| Multiple Outputs | - | Yes | - |
| Local History | - | Yes | - |
| Claude OAuth | - | Yes | - |
aptu pr create --diff <file> applies a patch, commits, and opens a PR. Structural graph context injects petgraph BFS blast-radius context into pr review prompts (opt-in, --features graph for the CLI; deep: true for the Action). Multiple providers: Anthropic, Cerebras, Gemini, Groq, OpenRouter (default), Z.AI, and ZenMux; free-tier models available via OpenRouter. Claude OAuth authenticates via ~/.claude/credentials.json (written by the Claude desktop app); no API key required. See Security for why the OpenSSF badge matters.
Architecture Benchmark
Head-to-head comparison of aptu+mercury-2 (Mercury 2, a small diffusion-based LLM by Inception Labs) vs a raw claude-opus-4.6 call (no schema, no rubric, no AST context) across 6 fixtures (3 triage, 3 PR review).
| Arm | Quality (mean, /5) | Cost/call | Latency p50 |
|---|---|---|---|
| aptu+mercury-2 | 4.8/5 | $0.0011 | 1,934 ms |
| raw claude-opus-4.6 | 2.2/5 | $0.0193 | 16,032 ms |
This compares a structured-harness call against an unstructured large-model call with no schema, rubric, or AST context; it illustrates the architecture pattern, not model capability.
aptu+mercury-2 is 17x cheaper and 8x faster than a raw claude-opus-4.6 call, while scoring more than twice as high on the structured rubric. See docs/BENCHMARKS.md for full methodology, fixture breakdown, and C1-C5 scores (n=1 per fixture).
Demo

CLI and Action Installation
The CLI and GitHub Action are self-managed entry points: install and configure them yourself. For a zero-setup, org-wide rollout, use the GitHub App instead.
# Homebrew (macOS/Linux)
# Cargo-binstall (fast)
# Cargo
Quick Start
Observability
See docs/GITHUB_ACTION.md for full field reference.
Security Scanning
Aptu includes built-in security pattern detection for PR reviews. Scanning is performed locally, and no code is sent to external services.
See docs/SECURITY_SCANNING.md for SARIF upload and GitHub integration.
Prompt Customization
Aptu's built-in system prompts are compiled into the binary as defaults. You can override them per operation at runtime or append project-specific guidance globally.
See docs/CONFIGURATION.md for file paths, operation names, and examples.
GitHub Action
Auto-triage new issues with AI using any supported provider.
- name: AI issue triage and PR review
uses: clouatre-labs/aptu@83226816caaec41ee93af5e1ca7c974b76de35ba # v0.10.10
with:
github-token: ${{ secrets.GITHUB_TOKEN }}
openrouter-api-key: ${{ secrets.OPENROUTER_API_KEY }}
Options: apply-labels, no-comment, skip-labeled, dry-run, model, provider.
See docs/GITHUB_ACTION.md for setup and examples.
Configuration
See docs/CONFIGURATION.md for AI provider setup.
Models
Use aptu models list to discover available models from all configured providers.
Discovering models
aptu models list # all providers
aptu models list --provider openrouter # OpenRouter only
Filtering and sorting
| Flag | Description |
|---|---|
--provider |
Filter to a specific provider |
--sort name|context |
Sort by name or context window size |
--min-context N |
Show only models with at least N tokens of context |
--filter TEXT |
Filter by name or ID (case-insensitive substring match) |
Free-tier models
OpenRouter exposes pricing data for each model. Models with zero prompt and completion cost are labeled free in the output. Use --provider openrouter to browse free models.
Security
This policy is backed by enforced controls: GPG-signed commits, Developer Certificate of Origin, required code owner review, SLSA Level 3 build provenance, and OpenSSF Best Practices Silver. These are not decorative. They ensure that a named, verified human is accountable for every change that reaches users.
- SLSA Level 3 - Provenance attestations for all releases
- REUSE/SPDX - License compliance for all files
- Signed Commits - GPG-signed commits required
- Dependency Scanning - Automated updates via Renovate
See SECURITY.md for reporting and verification.
Architecture
Aptu assembles structured context (AST, call-graph blast radius, security scanner output, and dependency release notes) before any AI call. A prompt-injection byte cap and local-only security scanning ensure no raw source code is sent to external services without explicit review. The GitHub App, CLI, and GitHub Action share a common aptu-core library; see docs/ARCHITECTURE.md for the full crate structure, data flow, and key dependencies.
Roadmap
See docs/ROADMAP.md for the project direction across near-term, medium-term, and long-term horizons.
Contributing
We welcome contributions! See CONTRIBUTING.md for guidelines. See docs/REPO-STANDARDS.md for a full artifact map and rationale covering CI workflows, tooling, and security controls.
License
Apache-2.0. See LICENSE.