Tools & Products

OpenAI Makes ChatGPT Auto-Review Free for All Signed-In Accounts: Sandboxed PR Audits and Static Analysis

OpenAI opened its automated code review utility, ChatGPT Auto-Review, to every user authenticated with a standard ChatGPT account. The tool executes sandboxed static analysis, flags security vulnerabilities in pull requests, and runs without a paid Codex or Team subscription.

By Julian Thorne · 2026-10-06 · 10 min read

OpenAI expanded access to ChatGPT Auto-Review on October 6, 2026, granting free access to anyone logged in with a standard ChatGPT account. Originally introduced as an enterprise-only add-on for Codex and Team workspaces, Auto-Review automates line-by-line pull request analysis, static bug detection, and architectural compliance checks.

The zero-cost rollout allows independent developers and small open-source teams to run automated code reviews without commercial API tokens or paid seat tiers.


Sandboxed Architecture: Firecracker Isolation

Running automated reviews across arbitrary codebases introduces security challenges. To prevent untrusted dependencies or malicious test scripts from compromising infrastructure, OpenAI routes Auto-Review executions through microVM sandboxes:

┌────────────────────────────────────────────────────────────────────────┐
│                   ChatGPT Auto-Review Execution Pipeline               │
├────────────────────────────────────────────────────────────────────────┤
│ 1. Ingestion: GitHub Webhook or Local Diff via CLI                     │
│ 2. Isolation: Spawn AWS Firecracker microVM (jail: read-only root)     │
│ 3. AST Parsing: Tree-sitter syntax extraction & Symbol Graph           │
│ 4. Inference: Targeted GPT-4o-mini / Codex review passes               │
│ 5. Output: Structured Markdown findings + In-line patch suggestions   │
└────────────────────────────────────────────────────────────────────────┘

Because reviews run in isolated containers, user code files are flushed from memory immediately upon review completion and are excluded from foundation model training.


Review Capabilities: What the Free Tier Detects

Auto-Review operates beyond basic linting tools like ESLint or Ruff. The engine inspects logic flow, concurrency handling, and credential leaks:

Check Category Detection Mechanism Example Vulnerability Flagged
Concurrency & Deadlocks Channel & Mutex state tracking Unbuffered Go channel blocking parent goroutine
Memory Management Lifetime and pointer analysis Dangling pointer reference in C++20 move assignment
API Secret Leaks High-entropy regex & context match Hardcoded AWS secret key in test mock fixtures
SQL & Query Safety ORM parameter binding check Unsanitized raw string concatenation in Prisma query
Type Invariants Strict TypeScript / Rust checker Unhandled nullable union variants causing runtime exceptions

Integrating Auto-Review in Development Workflows

Developers can trigger Auto-Review through three interfaces:

  1. ChatGPT Web UI: Paste a raw git diff or repository link into the ChatGPT prompt and select the Review Code action button.
  2. GitHub Action: Install the official openai/auto-review-action@v2 in your repository workflow file:
name: Automated Code Review
on: [pull_request]

jobs:
  review:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: openai/auto-review-action@v2
        with:
          chatgpt-token: ${{ secrets.CHATGPT_ACCOUNT_TOKEN }}
          severity-threshold: "medium"
  1. OpenAI CLI: Run chatgpt review --staged directly in your terminal before committing changes.