AI Reviewers Approve Malicious Code Due to "Pre-Approved" Label
Security researchers have exposed a flaw in AI-based code review systems. The systems allowed code containing secret exfiltration to be shipped. This occurred
Security researchers have exposed a flaw in AI-based code review systems. The
systems allowed code containing secret exfiltration to be shipped. This occurred
because the pull request was labeled as "pre-approved." The AI relied on the
text label rather than analyzing the actual code. This demonstrates a blind spot
in automated security verification tools. It highlights the danger of implicit
trust in metadata over content analysis. The experiment shows how easily
automation can be bypassed by simple social engineering. Developers are warned
to verify code regardless of automated approval status.