Checklist for Reviewing AI-Generated Code Mohamad Charafeddine — mohamadcharafeddine.com/en/resources/ai-code-review-checklist/ ======================================== ── Before review ── // GET /api/bookings/:id app.get('/api/bookings/:id', async (req, res) => { const booking = await db.bookings.findById(req.params.id); // [1] res.json(booking); // [2] }); const SMS_API_KEY = 'sk_live_EXAMPLE_ONLY'; // [3] ── After review ── // GET /api/bookings/:id app.get('/api/bookings/:id', requireLogin, async (req, res) => { // [1] const booking = await db.bookings.findById(req.params.id); if (!booking || booking.patientId !== req.user.id) { // [2] return res.status(404).json({ error: 'Not found' }); } res.json({ // [3] id: booking.id, date: booking.date, status: booking.status, }); }); const SMS_API_KEY = process.env.SMS_API_KEY; // [4] ── Before review ── // POST /api/contact app.post('/api/contact', async (req, res) => { const { name, phone, message } = req.body; // [1] await db.query( "INSERT INTO messages (name, phone, message) VALUES ('" + name + "', '" + phone + "', '" + message + "')" // [2] ); res.send('Thanks ' + name); // [3] }); ── After review ── // POST /api/contact (rateLimit: illustrative, use your framework's limiter) app.post('/api/contact', rateLimit({ max: 5, perMinutes: 10 }), async (req, res) => { const name = String(req.body.name || '').trim(); // [1] const phone = String(req.body.phone || '').trim(); const message = String(req.body.message || '').trim(); const phoneOk = /^[0-9+ ]{7,20}$/.test(phone); if (!name || name.length > 80 || !phoneOk || message.length > 1000) { return res.status(400).json({ error: 'invalid_input' }); } await db.query( // [2] 'INSERT INTO messages (name, phone, message) VALUES ($1, $2, $3)', [name, phone, message] ); res.json({ ok: true }); // [3] }); ── Code review prompt ── Review the following code as a strict security reviewer. Do not rewrite it all. 1) Explain what it does in 5 lines. 2) For each route: does it check sign-in? Ownership or role? 3) Where is user input used without validation or escaping? 4) Are any secrets or settings hard-coded? 5) What happens when each external call fails? 6) Which three most important tests are missing? Order findings from most to least serious, with line numbers. Code: [paste code after replacing any real key or data with fake values]