Explainer
Security review for pull requests written by Claude Code
Claude Code writes the change in your terminal, and the pull request it becomes can open with no session attached. This page is who reads it for security: Claude Code's own review modes, your own checklist, and a second reviewer installed on the repository.
Tristan Roth,
Short answer: the pull request is the place to look, whoever wrote it. Two habits cover most of it. One: a security pass inside your own workflow; Claude Code ships review modes of its own, from a pass in your session to a code review on the pull request. Two: a reviewer installed on the repository, which reads every supported pull request as it opens, live on install, session or no session. The Aevral GitHub App is the second kind: install it on the repositories you choose, and from the next pull request, including the ones Claude Code opens, it looks for access control, business logic, injection and output classes on the diff, and posts an advisory Check on the head commit plus inline comments on the added lines when there is a grounded finding, at most five per review, each with a suggested fix. Public repositories are free, and paid plans start at $49 per organization per month (prices exclude VAT and other taxes).
What Claude Code work becomes
Claude Code is Anthropic's coding agent in your terminal. It writes the change while you watch the files change, and nothing ships until you say so. The change becomes a pull request, and the pull request can open without the agent's name on it: a branch pushed from a cloud run, or a change proposed in a comment, lands in the same review queue as the ones a human wrote. A reviewer sees a diff, not who wrote it.
What changes with an agent is pace and intent. It writes what the task asked for, and the task rarely asks for the ownership check. The gate the old code enforced, the tenant binding in the query, the role list on the route: none of those are in the prompt, so none of them are guaranteed to be in the diff. Every line in the diff answers the task, which is why the diff looks clean while the rule behind it moved.
What a security read of that pull request looks for
The same two questions a human review asks. On this route, who is the actor and where does the gate for it live. On this lookup, who names the key, the session or the request. Access control first, because it is the class that disappears quietly: a missing tenant check on a new endpoint, a fetch by id with no owner scoping, a role list grown by one.
The injection and output classes ride in on features. A sort or filter parameter that reaches raw SQL, a shell string built from input, markdown rendered as HTML, a model response passed downstream unvalidated. In agent-written pull requests they arrive for the same reason as the access bugs: the task asked for the feature, and the feature is what got written.
Your options, in order of reach
Claude Code's own review modes. Anthropic documents a security review pass inside a Claude Code session, and a Code Review mode that reads pull requests and leaves findings as inline comments. The pass runs in the session, on your instruction; Code Review works on the pull request itself. A pull request that arrives from a cloud run or a comment, with nobody at the terminal, can still get the same read from a reviewer installed on the repository.
Your own checklist. Open the rule before the diff, name the actor, and stop at the four shapes worth stopping for. The procedure is written up in the access-review guide, and it costs the one thing a long queue is short of: attention.
A second reviewer on the repository. The Aevral GitHub App installs once, on the accounts or organizations you choose, and from the next pull request it reads the diff, live on install, the same reading for the pull requests a human wrote and the ones Claude Code wrote. A finding is a lead with evidence and a suggested fix, at most five findings per review, advisory and never blocking. You decide what ships.
From install to the first comment
One: install the Aevral GitHub App on the repositories you choose; a GitHub owner or admin approves the install. PR review is live on install: installing the App starts reviews on the next pull request, even before anyone signs in, and the owner can turn them off in Setup.
Two: sign in to the console with GitHub. That connects the install and starts a 14-day trial for private repositories: private reviews are free up to 500, and the trial ends at 14 days or 500 reviews, whichever comes first.
Three: open a pull request, or let your coding agent open one. Aevral reads the diff of the changed files, and the most security-relevant in full.
Four: read the result on the pull request. An advisory Check sits on the head commit, and when there is a grounded finding, inline comments sit on the added lines, at most five findings per review. Each finding carries the evidence, a suggested fix, and a Fix with your agent prompt a human can paste into Claude Code, Cursor, or Codex. Aevral never pushes, applies, or merges anything, and it never blocks a merge. You decide what ships.
What it looks for, and the published record
Aevral's PR review looks for access control, business logic, SQL and command injection, XSS, SSRF, path traversal, unsafe deserialization, token and session flaws, and LLM-integration risks, live on install. Access control is the first item on that list and the reason the product exists. The whole-repo scan reads authorization, IDOR, and business-logic access control across the default branch, for the rules a single diff does not show.
The published record: on the Aevral receipts page, the PR review runs of 25 September 2026 read "10 of 12" (Run 1) and "11 of 12" (Run 2) on the frozen authorization slice of planted pull requests. In the page's own words: "Each recall number is the result of that named run on that corpus. It is not a product accuracy rate, and results on your code depend on your code."
Limits worth knowing: GitHub only (not GitLab, Bitbucket, or Azure DevOps). The review reads the diff of the changed files and the most security-relevant files in full; on a large pull request the most security-relevant files are reviewed first, and the review says which files it covered. It is not secret scanning, not dependency scanning, and not a general SAST.
Sources
Claude Code docs: Claude Security; Claude Code docs: Code Review; Aevral receipts.
Read next
Security review for the pull requests Claude Code work becomes; Reviewing a pull request for access control; Handing a security finding to your coding agent; Vibe coding security: who reads the diff; Install the GitHub App; Pricing.
More guides
- What a whole-repo authorization scan reads
- PR security review and SAST are different questions
- Handing a security finding to your coding agent
- The Aevral launch-updates list, explained
- Reviewing a pull request for access control
- Working a scan report of access-control leads
- How IDOR happens in multi-tenant code
- Where access control hides in business logic
- Reviewing a pull request that wires in an LLM
- Security review priced per pull request, explained
- Reviewing pull requests for IDOR with a GitHub app
- Spotting a missing tenant check in a pull request
- Next.js and Supabase: the authorization check before launch
- Vibe coding security: who reads the diff