Policy toward each vendor's terms
Last updated 2026-10-08日本語All documents
ReviewFixLoop runs coding agents made by other companies. This page states what ReviewFixLoop does and does not do with them, and what we know about each vendor's terms. It is information, not legal advice. Under the Terms of Service, you are responsible for the authentication method with which you run each vendor's tool and for complying with each vendor's terms.
Terms used on this page
- Harness: a coding agent program, such as a vendor's command-line tool (a "vendor CLI").
- Manifest: a declarative file that tells ReviewFixLoop how to launch a harness. An official manifest is maintained by WillBooster. A community manifest is registered by a third party.
- Reviewer: a combination of a harness, a model and an effort setting that reviews a pull request.
- Resolver: the coding agent that conducts a review of a pull request: it decides how to treat each finding and changes the code.
- Run: one execution of the review-and-fix loop on one pull request.
- Job: one execution of a reviewer in a run.
Officially supported harnesses
| Harness | How it is launched |
|---|---|
| Claude Code | claude -p --output-format stream-json |
| Codex | codex exec --json |
| Google Antigravity | The ACP server of agy |
| GitHub Copilot CLI | copilot -p --output-format json |
| OpenCode | opencode run --format json |
The official manifests only launch the unmodified vendor CLI that you installed and configured, on your machine. ReviewFixLoop does not distribute the vendors' executables.
ReviewFixLoop is not involved in authentication
- You decide, in the vendor CLI's own settings, which authentication method it uses: an API key, a subscription, a cloud provider, or an account login. ReviewFixLoop does not choose it, verify it or record it.
- ReviewFixLoop does not change environment variables or settings related to authentication.
- ReviewFixLoop does not read, store or relay credentials. It does not show a login screen.
The reason is that ReviewFixLoop cannot know which authentication method a vendor CLI actually used. Even if it tried to guarantee a particular method, the CLI could switch to another one, for example when an API key is wrong. A guarantee would be a promise that cannot be kept.
What the vendors' terms prohibit developers from doing with users' credentials is showing a login screen, collecting or relaying credentials, and routing users' requests through the developer's own credentials. Launching a vendor CLI that you installed and configured is none of these. A vendor's terms can restrict more than that: the sections below state what applies to each vendor, such as Google's restriction on using Antigravity with products Google does not provide.
Service-side classifiers
The Service's classifiers send findings to external AI models. These requests use the Service's own credentials and include findings from private repositories. They are separate from the vendor CLIs running on your machine with your credentials. Data flow describes the content sent.
Your responsibility
- Which authentication method runs a vendor CLI, and compliance with each vendor's terms, are your responsibility. The risks of each authentication method are described on this page as information.
- Which reviewers are used is decided by your configuration. ReviewFixLoop does not ask for separate consent to a risky use, because the configuration itself is your choice.
- Community manifests are treated in the same way. You use them at your own responsibility.
Claude Code
The following documents from Anthropic determine this policy.
- Legal and compliance:
- A product that embeds Claude Code agrees to the Commercial Terms. It does not modify Claude Code, does not remove the built-in authentication methods, and does not take over, resell or intermediate its users' usage. Each user authenticates with their own API key, subscription or cloud credentials.
- Third-party developers do not embed the claude.ai login in their applications and do not collect, store or intermediate claude.ai credentials or session tokens.
- However, a user logging in to an unmodified Claude Code with their own subscription is not prevented.
- A post by Claude Devs (2026-05-13): third-party tools built with the Agent SDK (Conductor, OpenClaw) run on Claude plans.
- Help Center: use of the Agent SDK,
claude -pand third-party applications is drawn from the subscription's usage allowance.
The only mechanisms that have been sanctioned are those that extract OAuth tokens and call the API directly while impersonating Claude Code. The legal demand to OpenCode and the suspensions of January 2026 are examples. As of September 2026, we have found no case of a suspension for merely launching an unmodified Claude Code.
How ReviewFixLoop handles Claude Code:
- The official manifest launches the
claudethat you installed. ReviewFixLoop does not bundle Claude Code. - ReviewFixLoop does not change the system prompt. It passes the task as a user message. The reason is that a server-side classifier, when an appended system prompt looks like a third-party tool, routes the usage to extra usage billing instead of the subscription's allowance, and refuses the request with a 400 error for users who have not enabled extra usage. This rerouting was still reported in September 2026, but in every report the system prompt had been appended with
--append-system-prompt.- In WillBooster's internal use, 4,240 Claude jobs ran on a subscription without changing the system prompt and never received this 400 error (2026-08-20 to 2026-09-30).
- When ReviewFixLoop detects this 400 error (
Third-party apps now draw from your extra usage), it does not retry. It shows the reason and the remedies (enabling extra usage, or switching to an API key) and removes that reviewer from the run as unavailable. - The
.claude/settings.jsonof the repository under review is read, just as when you open Claude Code there yourself. This is Claude Code's own trust model, and ReviewFixLoop does not change it. - Using Claude Code with the ReviewFixLoop skill installed as the resolver is ordinary use of Claude Code.
- WillBooster agrees to the Commercial Terms.
- WillBooster does not make inquiries to Anthropic about this policy.
Google Antigravity
The following documents from Google determine this policy.
- Google Antigravity Additional Terms of Service, section 6: it prohibits using the service in combination with products that Google does not provide. Using Antigravity's OAuth with third-party software is stated as an example of a breach.
- The preamble of the same terms: when the service is used through one of the following, the terms accepted by the administrator apply instead of these terms. A Gemini API key from Google AI Studio is not among them.
- Gemini Enterprise (Google Cloud) or Gemini Enterprise for Business
- A Google Workspace subscription
- An API key for Gemini Enterprise
- FAQ: it names Claude Code as an example of third-party software that must not be used with the Antigravity login. To use Gemini from a third-party agent, it recommends Gemini Enterprise or a Google AI Studio API key.
- Documentation of the IDE extensions: Google distributes an ACP server that other companies' editors (such as Zed and JetBrains) launch. The documentation states that it works with the personal Free, Pro and Ultra logins.
The enforcement situation is as follows.
- The mass suspension of February 2026 targeted only token reuse and proxies.
- Since then, users who use only the official CLI or IDE have also been suspended by automated detection. There are reports of false positives in June 2026, of a user who ran the official
agy --printfrom cron, and of entire Google accounts being disabled. - The reason for a suspension is not disclosed, and a second violation results in a permanent suspension.
- No Google employee has confirmed in writing that a third-party product may be used in this form.
How ReviewFixLoop handles Antigravity:
- The official manifest launches the ACP server of the agy that you installed. This is the launch method that Google's documentation accepts for use from other companies' tools with a personal login.
- Whether Antigravity runs on a Google account login is decided by your configuration. Because of the risks above, and following Google's FAQ, we recommend using a Gemini API key or Gemini Enterprise.
Limits on vendor CLI usage
You can set, for each combination of your account and a harness, a maximum number of concurrent jobs and a maximum number of jobs per rolling 24 hours. The default is no limit.
- ReviewFixLoop sets no default because it cannot judge what is safe. Each vendor's usage allowance differs by plan and changes without notice. A default value would be taken as an assurance of safety.
- We advise you to set limits that fit your usage allowance with each vendor. When you start a run for the first time with a harness that has no limit, the same advice is shown with a link to that vendor's explanation of its usage allowance.
- A limit is an integer of 1 or more. It is stored in your account and changed with a CLI command, so that the same limit applies across your machines.
- A job beyond the concurrent limit waits for its turn. A reviewer beyond the 24-hour limit is removed from the run as unavailable. This is not treated as a failure.
Cursor CLI
Cursor CLI is not supported. Cursor's terms of use, read literally, prohibit automated access such as by scripts. We do not seek written confirmation from Cursor.
Product naming
ReviewFixLoop does not include "Claude Code", "Codex" or "GPT" in the names of its own products and features. Naming a vendor's CLI in a leaderboard row is a statement of fact.