One agent, infinite workflows. Configure Pullfrog to review new PRs, auto-address new human reviews, triage/label issues, make plans and PRDs, autofix CI, autofix merge conflicts, or anything else—just mention @pullfrog to assign tasks.

Trusted by teams at

Pullfrog is a GitHub bot that runs AI agents on your repo. It listens for GitHub events—PRs opened, issues created, reviews submitted, CI failures—and triggers agent runs based on your configuration. Toggle automations on or off from the dashboard, customize instructions per trigger, or tag @pullfrog for anything ad-hoc.
The agent comes with a purpose-built MCP server for performing git and GitHub-related operations like creating PRs, leaving reviews and comments, and reading CI logs. Shell commands are run in an isolated subprocess without access to sensitive environment variables. A headless browser tool is provided out-of-the-box.
All agent runs happen in your repo's GitHub Actions via a special pullfrog.yml workflow. Use (billed at raw provider cost, no markup), or bring your own key (or Claude subscription).

Works with any LLM provider: Anthropic, OpenAI, Google, Mistral, DeepSeek, OpenRouter, and more. Switch models with a config change to stay state-of-the-art. All API keys are stored as GitHub secrets.

Once you've added the .github/workflows/pullfrog.yml workflow, Pullfrog can trigger workflow runs programmatically in response to incoming webhook events. The pullfrog/pullfrog GitHub Action installs and spawns the agent with appropriate permissions and instructions.

All API keys are stored using GitHub's secret management system. The action auto-masks all keys and passes the minimum necessary environment variables through to the agent. All GitHub-related actions are performed using a short-lived installation token that is auto-revoked when the run completes.

No new UI to learn. Trigger agent runs with an at-mention anywhere in your repo. It pulls in the relevant context from where it was tagged and figures out what to do.

Configure automated agentic responses to common events, like new issues or pull requests. Use custom prompts to customize the agent's behavior.

Pullfrog automatically addresses reviews on PRs it creates. Just leave review comments as you would for a human colleague. Pullfrog will handle it and keep you posted as it works.

Like a good human colleague, Pullfrog detects CI failures on its own PRs and attempts a fix. It can be configured to attempt CI fixes on human-created PRs too.

Pullfrog's console relies on GitHub's own permission enforcement. Signed-in users can only see repos they already have access to. Organization-level settings require an organization owner; repository settings follow GitHub's repo permissions.

Shell commands are run in an isolated subprocess without access to sensitive environment variables. Git and GitHub operations go through a dedicated MCP server with permission checks — the agent can't push to protected branches or access repos it shouldn't.

A headless browser tool is provided out-of-the-box, giving the agent the ability to run end-to-end tests, take screenshots, and iterate on UI. Screenshots are uploaded to a secure S3 bucket—no extra configuration required.

Pullfrog provides agents with a purpose-built MCP server for performing git and GitHub operations — creating PRs, leaving reviews, reading CI logs, managing issues, and more. Every operation goes through Pullfrog's permission layer.
Free for developers on personal GitHub accounts. Organizations are $30/month with no per-run or per-seat billing.
Personal accounts and open source organizations
One predictable price. No per-run or per-seat billing.
Bring your own provider key, or an existing Claude Code or Codex subscription.
For multi-team organizations
Everything you need to know about Pullfrog.
Pullfrog is an AI-powered GitHub bot that can triage issues, review PRs, write code, make plans, and ship changes — all inside GitHub. It comes equipped with a purpose-built MCP server for safe git and GitHub operations, bash isolation, and a headless browser.
Pullfrog is open source, GitHub-first, and model-agnostic — it works with any LLM provider (Anthropic, OpenAI, Google, and more) rather than locking you into a specific vendor. It runs in your repo's GitHub Actions, so there's no new UI to learn. It includes bash isolation, a headless browser, configurable automations, and a purpose-built MCP server for safe git and GitHub operations — all out-of-the-box.
Pullfrog supports any LLM provider including Anthropic, OpenAI, Google, Mistral, DeepSeek, and OpenRouter. Add your provider's API key as a GitHub secret and you're ready to go.
You can trigger workflows by tagging @pullfrog anywhere, or configuring it to run automatically in response to certain events.
All API keys are stored as GitHub secrets, following the principle of least privilege. Only the minimum set of environment variables necessary for the agent to function are passed through to each run. GitHub automatically masks all secrets in logs to prevent accidental exposure.
All Git- and GitHub-related actions are performed using a short-lived GitHub App installation token that is automatically revoked at the end of each workflow run. This ensures that tokens never persist beyond their intended use and minimizes the risk of unauthorized access.
Best practices around secrets management and data security are automatically appended to all agent prompts, ensuring that agents are consistently reminded to handle sensitive information appropriately throughout their execution.
GitHub remains the single source of truth for organization and repo-based permissions. In an organization context, users can only see the repos that are visible to them on GitHub, ensuring that access control is consistent with your existing GitHub permissions. Organization-level settings require an organization owner; repository settings follow GitHub's repo permissions.
Pullfrog relies on GitHub itself to enforce these permissions. Each user's dashboard is populated with live data from the GitHub API using a user-scoped token. In this way, Pullfrog always reflect the current state of your GitHub organization, without requiring separate permission management in Pullfrog.
Pullfrog enables asynchronous development by letting you kick off agentic runs and let them work while you focus on other tasks. It's perfect for CI/CD integration and maintains context across multiple agent executions.