AI code review: check what your agents write

Use AI code review to have a second model read agent-written code after every turn: findings with severity, file:line links and a bounded feedback loop.

Solviera Teknoloji 6 min read Türkçe oku

AI code review means a second model reads the code an agent wrote and reports problems. The trap with agents is speed: an agent changes dozens of files in one turn, and reading all of it line by line gives back the time the agent saved you. A review step closes that gap; the agent’s output passes a second pair of eyes before you look.

This post covers how to have agent output reviewed, how to weigh the findings and how to keep the review loop under control.

Why review agent output separately?

The agent that wrote the code is blind to its own assumptions. When an agent marks a change “done”, it often misses:

  • Missing rollback or cleanup on error paths
  • Edge cases: empty input, concurrent requests, timeouts
  • Security: reusable tokens, unvalidated input
  • Unused imports, dead code, inconsistent naming

A second model reading the same code with a fresh context, looking only at the diff, notices these more easily.

What good AI code review looks at

Findings only help when you can act on them. A good finding has:

PartExample
SeverityHigh, medium, low
Locationsrc/auth/session.ts:88
Problem“A new token is issued before the old one is revoked.”
Why it matters“Token reuse isn’t detected.”

Severity sets priority. Location takes you straight to the line. Vague “improve the code” comments are no use at all.

When to review

Three approaches:

  1. Automatically after every turn. Review starts as soon as the agent finishes its turn, so problems are caught while the agent still has the context.
  2. Before merging. Review the whole diff before the branch goes into the main branch.
  3. On demand. Review a commit or the working tree you’re unsure about.

With agents, the first saves the most time, because problems surface before they spread to the next turn.

Automatic code review in AgentVera

AgentVera’s code review is turned on in the project settings and shows up in the Reviews tab of the right panel:

  1. Turn on automatic review in the project settings and pick a Claude model.
  2. Choose what gets reviewed: the commits from the turn, or all changes.
  3. Choose whether findings go back to the agent.
  4. When the agent finishes its turn, the review runs; findings are listed with severity and file:line links.

You can also review the working tree, staged changes or a single commit by hand.

Bound the feedback loop

Sending findings back to the agent automatically is tempting, but an endless loop is risky: the agent fixes one issue and introduces another, the review finds it, and on it goes. That’s why AgentVera limits feedback to at most two rounds in a row. After that, the call is yours.

How to weigh findings

You don’t have to accept every finding. A practical order:

  • High: security and data-loss risks. Fix before merging.
  • Medium: error paths, missing tests. Usually cheap to fix in the same turn.
  • Low: style, unused imports. Clean up in bulk or with automated tools.

Don’t hesitate to reject false positives. The reviewing model can be wrong too; you know the context best.

Combine review with other safety nets

Review alone isn’t enough. It’s stronger together with:

  • Tests: review catches logic errors, tests catch behavior errors.
  • Turns: if a review shows a turn went the wrong way, undo it with turns.
  • Notifications: get told on Telegram when an important finding appears.
  • Flows: add a review or test agent after the builder agent.

A sample review report

In one turn, the agent added a refresh token flow and made three commits. When the turn ends, the review produces:

SeverityFindingLocation
HighRefresh token reuse isn’t detected; a new token is issued before the old one is revoked.src/auth/session.ts:88
MediumThe database transaction isn’t rolled back on the error path.src/auth/store.ts:41
LowUnused import.src/auth/index.ts:3

What do you do with this?

  1. Send the high finding to the agent. It’s a security issue and the agent still has the context, so the fix is cheap.
  2. Add the medium finding to the same turn. Error-path behavior needs a test; ask the agent to write one.
  3. Batch the low finding. A linter or the next cleanup pass will handle it.

Once the agent fixes things, the review runs again. If findings are still open after the second round, the automatic loop stops and the decision is yours.

Picking a model and scope for review

Review has a cost too. Reviewing every turn with the strongest model can get expensive. A practical approach:

  • For everyday turns, pick a faster, cheaper Claude model.
  • Before merging, consider reviewing the whole diff by hand with a stronger model.
  • Limiting scope to the turn’s commits keeps the reviewed diff small; reviewing all changes also catches uncommitted work.

Feed review back into the agent’s role

If you see the same patterns in findings again and again, move them into the agent’s role. If the review keeps flagging missing error-path tests, add a line like this:

For every new function, write at least one error-path test next to the happy-path test.

Then the same issue stops showing up every turn; the agent prevents it up front. Over time the reports get shorter and the findings that matter stand out.

Reading reviews alongside history helps too. AgentVera’s conversation search runs full-text search across all Claude and Codex conversations, so you can find the session where an issue was discussed before and resume it in a new agent.

Checklist

  • Is automatic review on in the project settings?
  • Does the review scope (turn commits or all changes) fit your work?
  • Were high-severity findings closed before merging?
  • Is the feedback loop bounded?
  • Were the tests run independently of the review?

Wrapping up

AI code review lets you use agents’ speed without giving up quality. A second model reading the code after every turn catches problems while the agent still has the context, and findings with severity and location tell you where to look first.

In AgentVera you turn review on per project and send findings to the agent in one click. Use it with the merge steps in git worktrees for parallel agents, or start on the free plan.

Questions

Does AI code review replace human review?

No. It catches obvious bugs, missing checks and security holes early, but design decisions and business rules still need a person.

What does the review cover?

In AgentVera, when an agent finishes its turn, the commits from that turn or all changes are reviewed. You can also review the working tree, staged changes or a single commit by hand.

Do findings go back to the agent automatically?

If you want. Findings can be sent back to the agent, at most two rounds in a row so the loop doesn’t run away.

Which model does the review?

The Claude model you pick in the project settings.

Bring your agents to one desk.

Download AgentVera for free; your installed CLIs are ready to go.

More posts