Skip to main content

Security review

CodePeel can flag potential security issues in submitted changes and the context available to the review. Use its findings to guide investigation alongside your tests, dedicated security tools and human review.

What to look for

Security-related findings may concern exposed credentials, unsafe input handling, missing authorization, insecure configuration or data exposure. Coverage depends on the code, context and review result; this is not a promise to detect every vulnerability or cover every security standard.

A review of changed code is not an exhaustive audit of the repository. Relevant behavior may live in another service, runtime configuration, dependencies or code that was not available to the reviewer.

Investigate a finding

  1. Open the reported file and location in the reviewed revision.
  2. Trace the input, permissions and operation described by the finding.
  3. Confirm whether the condition is reachable and what impact it has.
  4. Inspect any suggested fix in context. Do not apply it blindly.
  5. Add a regression test where practical and rerun relevant checks.

For access-control findings, test with users from different accounts or roles. For webhook verification, check the actual bytes received and the framework's body parsing behavior. For injection findings, trace untrusted input into the operation rather than relying only on a suspicious-looking string.

If a credential is exposed

Do not paste the credential into review chat or a support message. Revoke or rotate it through the provider, check for unauthorized use and remove it from the affected code. Removing a credential from the latest commit does not erase it from repository history.

Use a dedicated secret scanner appropriate to your workflow. An AI review is not a substitute for credential management.

Suggested fixes

A suggested fix is a starting point for your review. Confirm that it preserves intended behavior, uses your project's actual APIs and handles failure paths. Some findings may require a broader design change and have no directly applicable patch.

See auto-fix for supported ways to work with fixes, or chat to ask for clarification.

Merge checks

See pre-merge checks for configuring review-related statuses. Enforcing a status also requires the appropriate GitHub branch protection or ruleset. A review comment alone does not prevent a merge.

A successful status or empty findings list does not establish that a change is secure. Keep relevant tests and required human approvals in place.

Review failures and missing findings

Check that the review completed and covered the intended changes. If the review reports a failure, unavailable provider or incomplete coverage, resolve that state before treating it as completed feedback. If an issue was missed, preserve the reviewed revision and a minimal reproduction for investigation.

Contact support with the repository, review time and a description of the behavior. Do not include live tokens, secrets or unnecessary private source code.

GitHub, VS Code and MCP

Security-related feedback is part of CodePeel's review workflows in GitHub, VS Code and MCP. The submitted changes and available context can differ between workflows, so do not assume their results will be identical.

How is my code handled?

Read Security and code handling for provider processing and retained review data, and the Privacy Policy for the broader policy. CodePeel is not a zero-retention service.