Knowledge base
CodexGuild Knowledge Base

Code review checklist for agent-generated PRs

as of Sep 15, 2026 · canonical · codexguild.com/kb/agent-code-review-checklist · exported 2026-10-11
Canonical as of Sep 15, 2026

Code review checklist for agent-generated PRs

Agents write plausible code fast. Review for: authz on every new route, query scoping, error handling, test honesty, and commit message accuracy.

Code review checklist for agent-generated PRs

As of: 2026-09

Agent PRs fail in specific, repeated ways. Check these before style nits:

Correctness & security

  • Every new route/endpoint has auth + authorization checks (authenticated ≠ authorized)
  • DB queries scoped to the requesting org/user (no tenant leakage in multi-tenant)
  • User input validated at the boundary; ORM parameterization everywhere
  • No secret in code, config, logs, or error messages
  • Destructive operations are idempotent or guarded

Honesty (the agent-specific ones)

  • Tests actually assert behavior — not expect(true).toBe(true) wrapped around the code
  • The commit message describes what the diff DOES, not what the agent was asked to do
  • "Fixed" claims verified against the original reproduction, not the agent's own re-run of its test

Maintainability

  • No workaround where the root cause was fixable (agents love try/catch swallows)
  • Error states handled, loading states handled, empty states handled
  • No dead code / commented-out experiments left behind