Security review for the pull requests Devin opens.
Devin opens pull requests and responds to comments on them, and a pull request can carry a teammate's name as its author. Aevral, the AI security reviewer for GitHub pull requests, reviews those pull requests within your plan's allowance, whoever the author field names, and gives the reviewer a copy-paste fix prompt with each finding.
In plain words
Picture a contractor who takes a ticket, works on it in their own workspace, and leaves a pull request for your team to review. Devin, from Cognition, is built for that hand-off: it writes, runs and tests code, then opens a pull request on GitHub. This page is about those pull requests and the security reading they get before merge.
How Devin gets to a pull request
From Cognition's own documentation. Each line is in our words, with the quote it rests on underneath.
The Devin docs describe it as an autonomous software engineer that writes, runs and tests code.
“Devin is an autonomous AI software engineer that can write, run and test code.”
Access to Devin runs through Cognition: a company working with Cognition requests permissions and uses Devin at app.devin.ai.
“If your company is already working with Cognition, you can request permissions from your Administrator or Cognition directly and access Devin via the web application at app.devin.ai”
Connected to a GitHub organization, Devin creates pull requests and answers comments on them.
“Integrating Devin with your GitHub organization enables Devin to create pull requests, respond to PR comments, and collaborate directly within your repositories.”
A comment that starts with /devin on an open pull request starts a Devin session that uses the pull request as context.
“On any open pull request in a repository connected to Devin, leave a comment that starts with /devin followed by what you want done: /devin fix the failing lint check and push a commit Devin starts a new session with that repository, uses the PR as context”
One workflow the Devin docs suggest is to hand Devin tasks in the morning and come back to draft pull requests.
“Carving out tasks from your todo list at the start of your day and returning to draft PRs waiting for review.”
Ask Devin and Devin Review are not the pull request author
Ask Devin is where you ask questions about how your code works.
“Ask questions about how your code works, explore architecture, dependencies, and key functions.”
Devin Docs, Ask Devin, read
For work, Ask Devin prepares a prompt that is ready to hand off to a separate Agent session.
“Devin generates a context-rich prompt based on what it learns, ready to hand off to an Agent session.”
Devin Review is a code review platform in the Devin web app, built to organize and explain large pull requests. This page is about the pull requests Devin writes, not about that review.
“Devin Review is a full-service code review platform within the Devin webapp that turns large, complex PRs into intuitively organized diffs and precise explanations.”
Devin Docs, Devin Review, read
Devin Review has its own security scanning, with CWE classes and severity levels.
“Detects security vulnerabilities and suggests hardening improvements, with CWE classification and severity levels.”
Why it matters: the author field may not say Devin
A reviewer often decides how hard to look by who wrote the change. With Devin, that signal can be gone: an admin can set Devin to open pull requests as the linked human, so the author field shows a colleague's name on code an agent wrote. A security reading that depends on noticing "this one came from the agent" can skip those pull requests.
Devin also stays with the pull request after it opens: it responds to comments on pull requests its sessions are working on, a /devin comment can ask it to push a commit, and the Devin docs recommend branch protection so required checks pass before Devin can merge. So the diff under review can change after the pull request opens, and a new commit can change what an endpoint allows. Aevral reviews a pull request when it is opened or reopened and when new commits are pushed, within your plan's review allowance, whoever the author field names, looking for access control, business logic and injection problems among its classes. It does not need to know that Devin wrote it.
What the vendor's docs say
With user linking, pull requests Devin opens in a person's sessions are authored by that person.
“individual users can link their own GitHub account to Devin so that Devin can act under their identity: pull requests Devin opens in their sessions are authored by them”
For pull requests to be opened as the linked user, an admin also has to set Devin's Open PRs as setting.
“For Devin to open pull requests as the linked user, an admin also needs to set Open PRs as”
Devin answers comments on pull requests its sessions are still working on.
“Devin automatically responds to comments on PRs its sessions are working on, as long as the session has not been archived.”
The Devin docs recommend branch protection so required checks pass before Devin can merge.
“We recommend enabling branch protection rules on your main branch to ensure all required checks pass before Devin can merge changes.”
Where Aevral fits: a copy-paste handoff
Aevral reviews a Devin pull request like any other pull request on a repository where the Aevral GitHub App is installed: when it is opened or reopened and when new commits are pushed, within your plan's review allowance. A finding is an inline comment on the added line, next to an advisory Check that never blocks the pull request.
Devin ignores comments from bots by default, so an Aevral comment on a Devin pull request does nothing on its own. The handoff is human: copy the Fix with your agent prompt, read it, and paste it into a new pull request comment that starts with /devin. If a Devin session is already on that pull request, the comment goes to it. Devin's docs also describe an allowlist of bots Devin responds to, which only organization admins can change; that is Devin's setting, and Aevral neither configures it nor relies on it.
By default, Devin ignores comments from bots, including code review bots.
“By default, Devin ignores comments from bot users (such as github-actions[bot] , dependabot[bot] , or code review bots) to prevent infinite feedback loops.”
Only organization admins can change that setting.
“Only organization admins can modify this setting.”
The setting can instead hold an allowlist of bot usernames that Devin responds to.
“You provide an allowlist of bot usernames that Devin should respond to.”
A /devin comment on a pull request Devin is already working on goes to that session.
“If a Devin session is already working on the PR, /devin comments are sent to that session instead of starting a new one.”
Devin Docs, start Devin from a PR comment (existing session), read
How the prompt is built and how to use it well: handing a finding to your coding agent.
Setup, the two human clicks
Two clicks, both yours: install the GitHub App on the repositories the agent works in, then log in to the console with GitHub. An agent cannot install the App or finish the login for you; it can read this page and the agent-setup prompt instead.
- Install the GitHub App: https://github.com/apps/aevral
- Log in to the console: https://app.aevral.com/login
- Official agent-setup prompt: https://docs.aevral.com/agent-setup/prompt.md
What this page does not claim
- Aevral is not affiliated with, endorsed by, or a partner of the company behind Devin. There is no integration between the two products: Aevral does not call Devin, and Devin does not call Aevral.
- Aevral never commits, pushes, applies or merges a change. The Fix with your agent prompt is text a human copies; what the agent does with it goes through your repository's own review and merge rules.
- PR review looks for a list of classes on the diff and leaves at most two findings per review. A finding is a lead with evidence, not a verdict, and a quiet review is not proof that the code is safe.
- The boxed statements about Devin come from the vendor's own documentation, each with the quote it rests on and the date it was read. The paragraphs around them are Aevral's reading of what those facts mean for a security review. Vendor products change; the vendor's docs win over this page.
- This page does not compare Aevral with Devin Review or rank either one. They can both read the same pull request.
- Aevral does not start Devin sessions, read Devin's workspace, or act on Devin's behalf.
Sources
Read next