Code review
AI code review
AI code review is the use of a large language model to examine a pull or merge request and post findings, questions, or suggested changes for a human reviewer to validate.
What it means
Google defines a code review as a process where someone other than the author examines the code. AI code review hands that first pass to a large language model: it reads a pull or merge request, can gather context from the whole repository, and posts comments, questions, and suggested changes the author can apply.
It is strongest on checks that used to be routine. Vijayvergiya et al. note in the AutoCommenter paper that verifying some coding best practices “is commonly left to human reviewers” and evaluate an LLM-backed system that learns and enforces them. Convention consistency, obvious defects, and missing tests follow the same pattern.
Vendors document the limits themselves. GitHub states that Copilot code review “is not guaranteed to spot all problems or issues in a pull request”, that it sometimes makes mistakes, and that a human review should supplement its feedback. Google’s reviewer guide adds that “a human must ensure that tests are valid”.
AI code review vs static analysis
Static analysis (see SAST) matches code against fixed rules. OWASP credits it with scaling well and running repeatedly in continuous integration, and faults it for high false-positive counts and for missing configuration issues that are not in the code. GitHub’s caveat that its reviewer sometimes makes mistakes and needs validation fills the other column.
| Question | Static analysis | AI code review |
|---|---|---|
| What it examines | Code against known rules | The diff, description, and repository context |
| What it returns | Rule matches with file, line, and snippet | Comments, questions, suggested changes |
| Known failure | Many false positives; blind to configuration | Mistakes and missed problems needing validation |
| Best use | Repeated automated gates | First-pass reader before a human decides |
Why it matters for AI-written code
When a coding agent writes the change, reviewer attention becomes the scarce step. GitHub’s instruction to always validate AI feedback with a human review means the model shortens the reading while the decision still lands on a person. Two risks are specific to a model reading untrusted changes.
- Prompt injection through the change itself. OWASP’s LLM01:2025 entry describes indirect prompt injection as an LLM accepting input from external sources such as files whose content alters its behavior in unintended ways. A pull request is such input; OWASP recommends segregating external content and human approval for high-risk actions.
- Rubber-stamping. A review that counts as approval invites merging on the model’s word. By default GitHub keeps Copilot’s review as a “Comment”, not an “Approve”, so it does not count toward required approvals.
How Enji Guard helps
Audits that rerun as the code changes, and fixes that follow, keep a project in the green zone; code review is one published Enji Guard workflow beside that loop. The published action “Activate code review” starts when a non-draft pull or merge request opens or when someone mentions the bot in a comment or note.
Each finding carries a severity label (blocking, important, minor, or positive), plain-language impact, evidence, and a next action. The rule against invented findings: “Avoid speculative findings. If evidence is weak, say so”; uncertainty goes into Limitations. Default scope: changed behavior and user impact, correctness and edge cases, security and privacy risks, tests and confidence, project conventions, migration or deployment risk, and unnecessary complexity.
Repository instructions such as AGENTS.md can shape review quality, language, and commands, and GUARD.md guidance can direct focus, exclude or reclassify findings, and change severity. Neither overrides mention safety, write boundaries, or honest severity, and guidance the pull request itself adds gets extra skepticism. Mention requests are classified first; command or code-change requests are refused.
Enji Guard’s code review does not modify files, create branches, commits, or issues, and does not approve, merge, or close the request; it posts only the reply the original provider thread allows. The repository owner and provider protections keep the final decision (see human approval).
Enji Guard