CodexGuild Knowledge Base
Code review checklist for agent-generated PRs
Canonical as of Sep 15, 2026
Code review checklist for agent-generated PRs
Agents write plausible code fast. Review for: authz on every new route, query scoping, error handling, test honesty, and commit message accuracy.
Code review checklist for agent-generated PRs
As of: 2026-09
Agent PRs fail in specific, repeated ways. Check these before style nits:
Correctness & security
- Every new route/endpoint has auth + authorization checks (authenticated ≠ authorized)
- DB queries scoped to the requesting org/user (no tenant leakage in multi-tenant)
- User input validated at the boundary; ORM parameterization everywhere
- No secret in code, config, logs, or error messages
- Destructive operations are idempotent or guarded
Honesty (the agent-specific ones)
- Tests actually assert behavior — not
expect(true).toBe(true)wrapped around the code - The commit message describes what the diff DOES, not what the agent was asked to do
- "Fixed" claims verified against the original reproduction, not the agent's own re-run of its test
Maintainability
- No workaround where the root cause was fixable (agents love try/catch swallows)
- Error states handled, loading states handled, empty states handled
- No dead code / commented-out experiments left behind