AI-Generated Code Audit System
Audit of AI-generated code for vulnerabilities in authorization, external data handling, secret storage, and dependency use. The system helps surface unsafe code before release.
The task
Build a system for reviewing AI-generated code and make it part of the application build process.
Scope of review
The checks cover authorization, handling of external input, secrets, dependencies and their provenance. Code analysis tools and review rules are used to find vulnerable constructs.
The solution includes Semgrep, CodeQL, Gitleaks and Trivy.
Working with findings
We combined the scanning tools with rules that warn or block the build. Findings are reviewed with the team and used to tune the controls.
Expert review determines which findings must be fixed and which rules should apply to future code changes.