OpenAI Makes ChatGPT Auto-Review Free for All Signed-In Accounts: Sandboxed PR Audits and Static Analysis
OpenAI opened its automated code review utility, ChatGPT Auto-Review, to every user authenticated with a standard ChatGPT account. The tool executes sandboxed static analysis, flags security vulnerabilities in pull requests, and runs without a paid Codex or Team subscription.
OpenAI expanded access to ChatGPT Auto-Review on October 6, 2026, granting free access to anyone logged in with a standard ChatGPT account. Originally introduced as an enterprise-only add-on for Codex and Team workspaces, Auto-Review automates line-by-line pull request analysis, static bug detection, and architectural compliance checks.
The zero-cost rollout allows independent developers and small open-source teams to run automated code reviews without commercial API tokens or paid seat tiers.
Sandboxed Architecture: Firecracker Isolation
Running automated reviews across arbitrary codebases introduces security challenges. To prevent untrusted dependencies or malicious test scripts from compromising infrastructure, OpenAI routes Auto-Review executions through microVM sandboxes:
┌────────────────────────────────────────────────────────────────────────┐
│ ChatGPT Auto-Review Execution Pipeline │
├────────────────────────────────────────────────────────────────────────┤
│ 1. Ingestion: GitHub Webhook or Local Diff via CLI │
│ 2. Isolation: Spawn AWS Firecracker microVM (jail: read-only root) │
│ 3. AST Parsing: Tree-sitter syntax extraction & Symbol Graph │
│ 4. Inference: Targeted GPT-4o-mini / Codex review passes │
│ 5. Output: Structured Markdown findings + In-line patch suggestions │
└────────────────────────────────────────────────────────────────────────┘
Because reviews run in isolated containers, user code files are flushed from memory immediately upon review completion and are excluded from foundation model training.
Review Capabilities: What the Free Tier Detects
Auto-Review operates beyond basic linting tools like ESLint or Ruff. The engine inspects logic flow, concurrency handling, and credential leaks:
| Check Category | Detection Mechanism | Example Vulnerability Flagged |
|---|---|---|
| Concurrency & Deadlocks | Channel & Mutex state tracking | Unbuffered Go channel blocking parent goroutine |
| Memory Management | Lifetime and pointer analysis | Dangling pointer reference in C++20 move assignment |
| API Secret Leaks | High-entropy regex & context match | Hardcoded AWS secret key in test mock fixtures |
| SQL & Query Safety | ORM parameter binding check | Unsanitized raw string concatenation in Prisma query |
| Type Invariants | Strict TypeScript / Rust checker | Unhandled nullable union variants causing runtime exceptions |
Integrating Auto-Review in Development Workflows
Developers can trigger Auto-Review through three interfaces:
- ChatGPT Web UI: Paste a raw git diff or repository link into the ChatGPT prompt and select the Review Code action button.
- GitHub Action: Install the official
openai/auto-review-action@v2in your repository workflow file:
name: Automated Code Review
on: [pull_request]
jobs:
review:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: openai/auto-review-action@v2
with:
chatgpt-token: ${{ secrets.CHATGPT_ACCOUNT_TOKEN }}
severity-threshold: "medium"
- OpenAI CLI: Run
chatgpt review --stageddirectly in your terminal before committing changes.