Blog
Practical notes for engineering leads. Honesty first: we do not claim 100% defect detection.
- Definitional · Article
What AI pull-request review is (and is not)
A practical definition of fail-closed AI code review: first pass against a versioned rule set, never sole approver, never silent LGTM when the model is down.
Read article → - Security · Article
OWASP LLM01 for AI code-review agents
How prompt injection shows up in PR diffs and commit messages, and how layered review should treat untrusted code as data — with honest limits.
Read article →