Reviewing AI Generated Code

Security-review discipline for code a language model wrote or completed: the failure patterns that show up more often in generated code and the review method that catches them. Covers hallucinated and confusable dependencies, insecure defaults and missing validation carried from training data, propagated vulnerable patterns, over-broad or fabricated permissions, and plausible-looking code that does not do what it claims. Use when reviewing an AI-authored change, an assistant's suggestion, or a large generated diff. Fluent is not correct.

UnboundCompute c72b815 6.2 KB Updated

File contents

UnboundCompute/security-agent-skills/tree/main/skills/reviewing-ai-generated-code commit c72b815777

Frequently asked questions

npx skillmds@latest add unboundcompute/reviewing-ai-generated-code