Coding agents write code the way they were asked to, and some requests lead straight to a known kind of security bug. Each page explains one class in plain words, shows why agents write it, the shapes it takes in a pull request, and one illustrated diff with what an Aevral finding on it looks like.
Aevral started with access control, so those classes already have longer walkthroughs. They are not repeated here.
What these pages do not claim
Aevral's PR security review, live on install, looks for these classes on the pull requests it reviews; looking for a class does not mean finding each instance of it. The whole-repo scan reads authorization, IDOR, and business-logic access control only. The diffs on these pages are illustrations, and the receipts are named runs of the whole eval suite. Where they mention a class, it is a small-corpus observation, not a performance estimate for that class.
One GitHub App. Reviews start when the App is installed. A Check on each pull request it reviews, with inline comments when there is a grounded finding. Free tier live: public repos free, 500/org/month, 25 private reviews a month. Paid plans are live in the console.
For professional use. By installing, you confirm you can act for the account or organization that owns it, and you accept the Terms and DPA on its behalf.