The Pipeline Mag Podcast

AI Code Reviewers Can Coach Attackers to Approval

A 4 October 2026 paper from Jingzhi Gong, Jie M. Zhang, Gunel Jahangirova and Meng Wang tests what happens when an attacker simply follows an AI reviewer’s comments, fixes what they point at and resubmits. On AFCRA-Bench, 159 pull requests drawn from real CVEs, the more detail the reviewer gave, the more often the attack succeeded.

The episode also covers the counterpoint: the attacker in the paper is unusually strong, every successful attack on Sonnet 5 was caught by at least one tested defense, and those defenses cost several times more than default review. Copilot was not tested, but GitHub now lets its approval count toward required approvals.

This episode was made from the article AI Code Reviewers Can Coach Attackers to Approval.