What to do
Review AI-generated code as untrusted third-party code. Confirm the patch solves the stated problem, inspect every changed line, run independent checks, and reject unnecessary complexity or unexplained dependencies.
Start with intent and scope
Read the task and diff before the generated explanation. Verify that the patch changes only necessary files and does not quietly alter public APIs, configuration, permissions, or dependencies.
Trace behavior
Follow inputs through validation, state changes, external calls, and returned values. Test empty, malformed, boundary, failure, and concurrent cases. Generated code often handles the happy path convincingly while missing system-specific invariants.
Demand independent evidence
Run existing tests and add cases that would fail if the patch were subtly wrong. Use linters, type checks, security scans, and manual inspection. Do not treat tests generated in the same pass as independent proof.
- Inspect new dependencies and licenses.
- Check logging for secrets or personal data.
- Confirm errors are observable and recoverable.
- Remove dead code and speculative abstractions.
Practical checklist
Continue researching
This guide is an editorial framework, not a product endorsement. Recheck vendor documentation and your organization's requirements before making a purchasing or security decision.