Security review for the pull requests Jules publishes.

Jules shows you a plan, but the security problem lives in the lines it writes. Aevral, the AI security reviewer for GitHub pull requests, reviews the pull request Jules publishes within your plan's allowance and gives you a copy-paste fix prompt with each finding.

In plain words

Picture leaving a sticky note on a colleague's screen, "fix the empty state on the billing page", and finding a pull request when you come back from lunch. Jules, from Google Labs, is built for that: you pick a repository and a branch, it proposes a plan, works in a virtual machine, and can publish the result as a pull request on GitHub. This page is about that pull request.

How Jules gets to a pull request

From Google Labs's own documentation. Each line is in our words, with the quote it rests on underneath.

  • The Jules docs call it an experimental coding agent for bugs, documentation and features.

    “Jules is an experimental coding agent that helps you fix bugs, add documentation, and build new features.”

    Jules docs, getting started, read

  • You pick a repository from the repo selector and choose the branch Jules works on.

    “Pick a repository from the repo selector. Choose the branch you want Jules to”

    Jules docs, getting started (repository), read

  • It clones your code into a virtual machine and modifies files there.

    “Jules runs in a virtual machine where it clones your code, installs dependencies, and modifies files.”

    Jules docs, getting started (first task), read

  • From Jules, you publish a branch or a pull request to GitHub.

    “Click Publish branch or Publish PR to push Jules' changes to GitHub”

    Jules docs, reviewing code changes (pushing to GitHub), read

  • Adding the label "jules" to a GitHub issue starts a task.

    “You can start a task from a GitHub issue by applying the label "jules" (case insensitive).”

    Jules docs, starting tasks from GitHub issues (label), read

  • When Jules finishes an issue, it links the pull request for you to review.

    “When Jules is finished with the issue, it will provide a link to the pull request where you can review its work.”

    Jules docs, starting tasks from GitHub issues, read

  • On GitHub, the app shows up as Google Labs Jules.

    “Find Google Labs Jules and click configure”

    Jules docs, FAQ (repository access), read

Plan review and chat are not the pull request

  • Jules shows a plan you can review and approve before it changes any code.

    “Once you submit a task, Jules will generate a plan. You can review and approve it before any code changes are made.”

    Jules docs, getting started (plan), read

  • You can talk to Jules in a chat box at any point.

    “At any point, you can use the chat box to talk to Jules.”

    Jules docs, reviewing plans (feedback), read

  • Jules can also scan a codebase on its own and propose implementation plans, as Suggested Tasks.

    “Jules can autonomously scan your codebase to identify areas for improvement and propose implementation plans.”

    Jules docs, suggested tasks (overview), read

  • Today that feature looks for #TODO comments that describe resolvable tasks.

    “The feature currently looks for #TODO comments that describe resolvable tasks.”

    Jules docs, suggested tasks, read

Why it matters: the plan can approve itself

Jules asks for a human at the plan, which is the right place for intent: which files, which approach. But a plan is not a diff. And if you walk away, Jules approves its own plan on a timer, so the first time a human reads what actually changed may be the pull request. A task can also start from nothing more than a label on an issue, or from a TODO that Jules found and proposed itself.

Security problems live in the lines, not in the plan. "Add an export endpoint for invoices" is a fine plan; whether the endpoint filters by the caller's organization is a line in the diff. Aevral reviews that diff when the pull request is opened, within your plan's review allowance, looking for access control, business logic and injection problems among its classes, and leaves its finding on the added line where the reviewer is already looking.

What the vendor's docs say

  • If you navigate away, Jules eventually auto-approves its plan on a timer.

    “If you navigate away, Jules will eventually auto-approve the plan, which is set on a timer.”

    Jules docs, reviewing plans, read

  • When Jules publishes the pull request, Jules is the pull request's creator.

    “When publishing a PR, Jules will appear as the creator of the PR”

    Jules docs, reviewing code changes (PR author), read

Where Aevral fits: a copy-paste handoff

Aevral reviews a Jules pull request like any other pull request on a repository where the Aevral GitHub App is installed: when it is opened or reopened and when new commits are pushed, within your plan's review allowance. A finding is an inline comment on the added line, next to an advisory Check that never blocks the pull request.

Each finding carries a Fix with your agent prompt. To hand it to Jules, a human copies the prompt, reads it, and starts a Jules task based on the pull request's branch, with the prompt as the task. What Jules publishes back to GitHub is reviewed again when it reaches a pull request, and your repository's own review and merge rules decide what ships.

  • A Jules task is based on the branch you choose.

    “Choose the branch you want to base your changes on.”

    Jules docs, running tasks, read

How the prompt is built and how to use it well: handing a finding to your coding agent.

Setup, the two human clicks

Two clicks, both yours: install the GitHub App on the repositories the agent works in, then log in to the console with GitHub. An agent cannot install the App or finish the login for you; it can read this page and the agent-setup prompt instead.

What this page does not claim

  • Aevral is not affiliated with, endorsed by, or a partner of the company behind Jules. There is no integration between the two products: Aevral does not call Jules, and Jules does not call Aevral.
  • Aevral never commits, pushes, applies or merges a change. The Fix with your agent prompt is text a human copies; what the agent does with it goes through your repository's own review and merge rules.
  • PR review looks for a list of classes on the diff and leaves at most two findings per review. A finding is a lead with evidence, not a verdict, and a quiet review is not proof that the code is safe.
  • The boxed statements about Jules come from the vendor's own documentation, each with the quote it rests on and the date it was read. The paragraphs around them are Aevral's reading of what those facts mean for a security review. Vendor products change; the vendor's docs win over this page.
  • This page does not describe Jules's plan review as weak. It says a plan and a diff answer different questions.
  • Aevral does not start Jules tasks, label issues for Jules, or read the Jules virtual machine.

Sources

Read next

Log inRead the machine facts: /llms.txt