GitHub guide outlines three-stage check for AI code security
GitHub has published a guide detailing a three-stage framework for verifying AI-generated code before publication. The article highlights that while AI models can produce functional code, security is often compromised. Citing a July 2025 Veracode study, it notes that 45% of code generated by over 100 AI models contained security flaws, with Java showing a failure rate over 70%. Additionally, a…
What you can do with it
AI at Work →Find outdated libraries with GitHub
What you get You catch security flaws and fake packages before your code goes live.
Scans code for vulnerabilities, secrets, and outdated libraries.
- Who for
- founders and operations
- Cost
- free tier
- Effort
- minutes
- Already included in
- Public repositories
Use it for
- Find outdated libraries
- Review AI code changes
How to set it up · From the article
- Enable Dependabot in your repository settings.
- Turn on secret scanning if your repo is public.
- Run a security review on your AI-generated code.
Watch out Secret scanning is free only for public repos; private needs paid plan
Not for everyone Paid plan only
Key points from the news
- Veracode found 45% of AI-generated code had security flaws in a July 2025 study.
- AI models fabricated package names at rates up to 21.7% in a USENIX Security 2025 study.
- GitHub recommends a three-stage check: human review, automated tools, and AI security review.
The proposed verification process divides responsibility among people, tools, and AI. The first stage requires developers to manually check for hardcoded secrets, permission logic, and input validation. The second stage leverages automated tools, specifically GitHub’s free Dependabot for vulnerability alerts and secret scanning for public repositories. The third stage involves using AI, such as Claude Code’s /security-review command, to perform a final security-focused review of the code flow.
The guide emphasizes that AI review should serve as a final safety net rather than a replacement for human and tool-based checks. It warns that newer models do not necessarily produce more secure code and advises developers to verify package existence on official registries like npm or PyPI to avoid installing malicious or non-existent libraries.
The story so far
4 episodes →- GitHub guide outlines three-stage check for AI code securitythis story
A Checklist for Verifying AI-Generated Code Before Publication: People, Tools, and AI
note.com · 4 October 2026
Loading the full article…
This text was published by note.com and written by しゃり. It is reproduced here with attribution so you can read it in full; the rights remain with the publisher. Read it at the source ↗
The headline, key points and digest above were generated by Digest AI's editorial model from the linked sources. Automated summaries can contain errors: the sources are the record. Spotted a mistake? Tell us. Published by Martin K., who runs Digest AI and handles corrections.
More in Marketing & Small Business
All →- OpenAI launches visual ad format in ChatGPT and expands measurement tools · 7 src
- Dropbox launches MCP for Grok Bot to streamline workflow · 1 src
- Google restricts Gemini model access for free and AI Plus users starting October 9 · 9 src
- SEO works better than AI referrals for conversions, study finds · 1 src
- Fractl's Nicole Franco presents entity-led digital PR workflow at maicon 2026 · 1 src
Comments
via GitHub Discussions