Developer builds open-source AI QA system to force rigorous code audits
Software developer Mohamed Saleh has released an open-source AI testing suite designed to prevent large language models from superficially approving flawed code. Frustrated by LLMs giving uncritical, overly positive code reviews, Saleh spent several weeks building a structured workflow that compels AI tools to conduct thorough audits. The system enforces up to 19 mandatory review phases — covering areas like OWASP Top 10 and state management — and requires the AI to cite exact file paths and line numbers for every finding. It also integrates runtime error data from Sentry and includes a 'red team' step where the AI attempts to bypass its own security fixes. Four specialized versions are available for backend, web, mobile, and desktop stacks, and are compatible with tools like Cursor and GitHub Copilot.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in