AI Code Review
Use AI as a first-pass reviewer: prompt focused passes for bugs, security, and clarity, with ranked, actionable findings.
TL;DR
- Run AI review in focused passes, correctness, security, readability, not one vague 'review this'.
- Ask for ranked, actionable findings: location, the problem, the risk, and a concrete fix.
- Treat AI review as a fast first pass that catches common issues, not a replacement for human review.
Focused Passes
CorrectnessHunt logic bugs, off-by-ones, and unhandled cases.
"Review only for correctness and
missing edge cases."SecurityLook for injection, auth gaps, secrets, and unsafe input handling.
"Review only for security: injection,
authz, secret leakage."ClaritySeparate pass for readability, naming, and complexity.
"Review only for readability and
naming. No behavior changes."Shape The Findings
Rank By SeverityAsk for the most serious issues first so you triage fast.
"List findings worst-first."Location + FixEach finding should name the line, the risk, and a concrete fix.
"For each: file:line, the risk, and
a specific fix."Failure ScenarioRequire a concrete input or state that triggers the problem.
"Give the exact input that breaks it."Keep It Honest
Allow 'No Issues'Let it pass cleanly instead of inventing problems to look useful.
"If nothing is wrong, say
'no issues found'."Confidence RatingsAsk it to mark each finding confirmed vs possible.
"Tag each finding: confirmed or
plausible."Review The DiffPoint the review at what changed, not the whole file.
"Review this diff: <paste diff>"Act On It
Verify FirstConfirm each finding is real before you change anything.
Reproduce the failure scenario,
then fix.Fix DeliberatelyApply fixes yourself or with a scoped prompt, not a blanket 'fix all'.
"Fix finding #1 only; leave the rest."Human Last WordKeep a person as the final approver of what merges.
AI first pass -> human approval.Tips
- Give the diff, not the whole file, so the review focuses on what changed.
- Tell it to say 'no issues found' for a clean pass rather than inventing problems to seem useful.
Warnings
- Models may flag false positives or miss subtle logic bugs; verify each finding before acting.
- AI review does not understand your product intent; it reviews code, not whether you built the right thing.
In Practice
Instead of 'review my code', this runs a single security-focused pass on a diff and demands ranked findings with a failure scenario and a fix, plus permission to find nothing.
- The prompt sets one lens, security, so the review goes deep instead of broad.
- It reviews the diff, concentrating attention on what changed.
- It requires each finding to include a concrete exploit scenario and a fix.
- It allows a clean pass, so the model is not pressured to invent issues.
Review this diff for SECURITY ONLY. Ignore style
and performance.
Look for: SQL/command injection, missing authz,
unvalidated input, secret or PII leakage in logs
or errors, and unsafe deserialization.
For each finding, give:
- file:line
- the vulnerability
- a concrete input/scenario that exploits it
- confidence: confirmed or plausible
- a specific fix
Rank worst-first. If you find nothing, say
"no security issues found" and stop.
<paste the diff>FAQ
Run focused passes with a clear lens, 'review only for security', 'review only for correctness and edge cases', and ask for ranked findings with a location, the specific risk, and a concrete fix. One broad 'review this' produces shallow, scattered comments.
Usually the diff, so the review concentrates on what changed and its immediate context. Provide surrounding code or types when the change depends on them, but reviewing an entire unchanged file wastes attention and context.
No. It is an excellent first pass that catches common bugs, missing edge cases, and security smells quickly, which makes human review more focused. But it does not understand product intent or team context, so a human still owns the final approval.
Expect some. Ask the model to rate its confidence and to explain the failure scenario for each finding. Verify the scenario is real before changing code. If a finding is wrong, say so and move on, do not let it push a needless change.