Set up a GitHub Action that checks AI-written code
Five minutes, one workflow file, no account and no API key. The checks run on your own runner, so code never leaves GitHub.
1. Add the workflow
Create .github/workflows/slopscore-code.yml:
name: SlopScore for Code
on: pull_request
permissions:
contents: read
pull-requests: write
jobs:
slop:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with: { fetch-depth: 0 }
- uses: kburrus64-max/slopscore-code@v1
with:
max: 40
comment: true
fetch-depth: 0 matters: the Action diffs against the PR's base branch and needs its history.
2. Read the results
- Annotations appear on the changed lines in the "Files changed" tab.
- Job summary shows the score, label and every finding.
- PR comment (with
comment: true) is one comment, updated on each push instead of piling up.
3. Choose when it fails
The check fails when the score is above max (default 40) or when any error-level finding appears (placeholder that drops code, undeclared import). Set fail-on-error: false to only use the score. Start with max: 70 on a busy repo and lower it over a few weeks.
4. Tune it
Add .slopscore-code.json at the repo root:
{ "max": 40, "failOnError": true, "ignoreRules": ["generic-name"], "ignorePaths": ["generated/", "migrations/"] }
Silence one line with a slopscore-ignore comment on it or on the line above. Lockfiles and vendored folders are skipped, and test files get lenient treatment.
5. Run it locally before pushing
npx github:kburrus64-max/slopscore-code --staged
Same rules, same score, so agents (and people) can fix findings before the PR exists. Many teams add this line to their CLAUDE.md or AGENTS.md so the agent runs it itself.
See every rule · try it on a public PR