frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Ask HN: Why aren't more people worried about AI impersonation in code reviews?

2•eranation•1h ago
This is something that has bothered me for quite a while, and I don't see a lot of people talk about it: Agents, in most cases, impersonate the human operator, by design, with no way to enforce, disclose, or control it. I believe this is causing an illusion of human in the loop, and is not intentional, and should be discussed.

For example:

All commits, pushes, PRs, and PR comments are all going to appear as the developer whether they wrote them or not. (You may have Co-authored-by, but not everyone has it set up).

The good: you are accountable for what your AI wrote.

The bad: while everyone should assume you used AI these days, there is still an expectation of some human-in-the-loop.

When your agent uses the GitHub MCP or CLI, it's most likely using an OAuth authorization (even if it's a GitHub app, you also give consent for it to act on your behalf)

This allows the agent to open PRs as you (which is intentional to force a 2nd reviewer. While you should review "your" own code, especially if AI wrote it, you shouldn't be able to also approve it). But it also allows it to comment or event approve PRs as the developer.

This indirectly means that we allow AI to review and approve its own code with an illusion of a human in the loop without leaving any traces.

E.g. Alice creates a PR using Claude Code (either locally or via the web).

Bob "reviews" it by checking out the branch and prompting their agent to run the /review-pr skill it helps with his token quota and leaderships expects 10x more features so he doesn't have time to actually read the code...

Since he has the GitHub MCP / CLI, this looks as if Bob wrote the comments (let's say they have a system prompt that removes emojis and em dashes... it will pass a turing test, that's if a human would have been reading his PR comments in the first place, but I'm getting ahead of myself). There is no explicit control that says they must disclose this is not really them who did the review, (and if there is, how would you detect or enforce it?)

Alice receives Bob's feedback + feedback from various other "AI Code Review" tools. She also needs to be tokenmaxing, so she asks her agent to /answer-pr-comments (fixing, or replying to comments as her)

Bob receives that, asks their agent to review Alice's responses and resolve the comments if they are addressed, or add more comments if anything was missed. (/re-review-pr skill)

You can use your imagination to see where this is going...

So at the end you can have a feature released to production where

- AI wrote the code

- The same AI (as in same model+harness) reviewed its own code (via a "PR")

- AI reviewed the review of the code and fixed / pushed back

- AI reviewed the review of the review, saw nothing was left and approved the PR (Bob asked Claude to "If you think it's prod-ready, approve it", nothing in the approval shows that Bob didn't even read the mermaid diagram or TL;DR summary of the PR...)

- CI passed the tests that AI wrote and AI reviewed

- AI auto-generated the documentation

- QA did "manual browser testing" by using computer use and a markdown file of test cases that AI generated, and confirmed manual testing is done

- E2E tests that AI wrote also pass so there is "no regression"

- code was shipped to production

- code initially works, but becomes slowly unmaintainable due to context rots, duplication, and eventually breaks in production

All audit trails show humans involved in various checkpoints of the feature. But all of this can happen without any of them doing anything but accept all changes (Simpsons depicted it great here: https://www.youtube.com/watch?v=R_rF4kcqLkI).

No one really asks developers explicitly not to do it, on the contrary, they are being asked to use AI more to produce more, so they do.

Is it just me who is worried about it?

Comments

goyozi•30m ago
As for why we are not worried enough, my guess would be that we’re too preoccupied with the impact on coding process itself, there isn’t enough attention put on other parts.

In terms of general working practices, there’s 2 things that I think are important right now: - proper AI attribution - both on commits and AI-generated PR comments. A bit of extra transparency can help spot these kinds of issues - clear separation of human and automated PR review

As an example, on that second point, we already use CodeRabbit for AI-based PR reviews. If I see „John” approving a PR, my expectation is that John himself read it and is vouching for it. I’d expect that AI is not involved or, at most, it does non-opinionated explaining and/or ordering of changes. If I see any kind of mention that „Claude did code review for someone”, I’m going to start screaming.

AI Agents Ran 27,000 Experiments. Their Biggest Discovery

https://medium.com/@vektormemory/660-ai-agents-ran-27-000-experiments-their-biggest-discovery-was...
1•vektormemory•10m ago•1 comments

ThinkPad: From IBM's Bento Box to Lenovo's AI Workstations

https://www.jdhodges.com/blog/thinkpad-history/
1•zdw•10m ago•0 comments

Tokenomics: Is it cost effective to refresh Claude's cache, or let it expire?

https://skids.dev/blog/anthropic-cache-tokenomics/
2•ryanskidmore•14m ago•0 comments

Installing a Payphone at My House

https://bert.org/2022/06/02/payphone/
1•skinfaxi•15m ago•0 comments

AI Wearables Are Coming but They'll Need to Pass the Coffee Shop Test to Survive

https://www.inc.com/connor-jewiss/ai-wearables-are-coming-but-theyll-need-to-pass-this-crucial-co...
3•connorjewiss•17m ago•0 comments

Ask HN: What are the system exists for execution of physical verifiable events?

2•abhishek2580•17m ago•1 comments

The Internet is not dead

https://blog.woblick.dev/en/2026/the-internet-is-not-dead/
1•Kovah•19m ago•0 comments

Two EA-18 fighter jets collide at Mountain Home airshow, pilots ejected safely

https://idahonews.com/news/local/two-f-18-fighter-jets-have-crashed-during-an-airshow-at-mountain...
2•ChrisArchitect•21m ago•0 comments

Peter G. Neumann, Who Warned of Computer Security Risks, Dies at 93

https://www.nytimes.com/2026/05/17/obituaries/peter-g-neumann-dead.html
3•rdl•23m ago•2 comments

Killing a `Cow` made my JSON formatter 42% faster

https://jacobasper.com/blog/killing-a-cow-made-my-json-formatter-42-percent-faster/
2•linolevan•23m ago•0 comments

Free 3D Mockup Video for Apps and Websites

https://www.freemockup.video/
1•buildwithdeni•24m ago•0 comments

GenCAD

https://gencad.github.io/
2•dagenix•26m ago•0 comments

Man vs. Machine [Live]

https://twitter.com/figure_robot/status/2056057735444394142
1•punnerud•27m ago•0 comments

Simpson's Paradox and the Hot Hand in Basketball (1995)

https://fermatslibrary.com/s/simpsons-paradox-and-the-hot-hand-in-basketball#email-newsletter
1•downbad_•34m ago•0 comments

Japan Team Successfully Test Engine for Mach 5 Aircraft, Eyeing 2HR Trip to US

https://mainichi.jp/english/articles/20260511/p2a/00m/0sc/015000c
2•karakoram•38m ago•0 comments

Show HN: Automated QA, Performance Tracking

https://malleon.io
1•godelshalt•39m ago•0 comments

LightInk: Solar E-ink smartwatch with LoRa and GPS lasts 10 months on one charge

https://www.notebookcheck.net/LightInk-E-ink-smartwatch-with-solar-LoRa-and-GPS-lasts-10-months-o...
1•HardwareLust•39m ago•0 comments

Linux 7.1-rc4 Released With Many Fixes

https://www.phoronix.com/news/Linux-7.1-rc4-Released
1•doener•41m ago•0 comments

In Defense of Operation Market Garden

https://secretaryrofdefenserock.substack.com/p/in-defense-of-operation-market-garden
1•baud147258•41m ago•0 comments

An AI Hate Wave Is Here

https://www.axios.com/2026/05/17/ai-backlash-polling-sentiment
4•karakoram•43m ago•4 comments

Microsoft is retiring Teams' Together Mode

https://www.theverge.com/tech/932215/microsoft-teams-together-mode
1•adunk•45m ago•0 comments

AI Is Starving for PDFs

https://mkotlikov.substack.com/p/your-ai-is-starving-for-pdfs
2•mkotlikov•45m ago•0 comments

Prolog Coding Horror

https://www.metalevel.at/prolog/horror
14•RohanAdwankar•50m ago•0 comments

We Lost Our Imagination

https://onatm.dev/2026/05/17/we-lost-our-imagination/
6•onatm•53m ago•3 comments

Looks like someone forgot to register this domain edwardgallrein.com – oopsie

https://replit.com/
1•ryanmerket•54m ago•0 comments

Dwarkesh in the Datacenter

https://marginalrevolution.com/marginalrevolution/2026/05/dwarkesh-in-the-datacenter.html
1•paulpauper•59m ago•0 comments

A New Kind of Family-Separation Crisis

https://www.theatlantic.com/politics/2026/05/honduras-deportations-without-children/687153/
1•paulpauper•59m ago•0 comments

My Son's Math Homework Is Essentially Just Pokémon

https://www.theatlantic.com/technology/2026/05/homework-video-games-ed-tech/687198/
1•paulpauper•59m ago•0 comments

Ask HN: Why aren't more people worried about AI impersonation in code reviews?

2•eranation•1h ago•1 comments

Release PiClaw v2.4.0 – The Infosphere · rcarmo/piclaw

https://github.com/rcarmo/piclaw/releases/tag/v2.4.0
1•rcarmo•1h ago•0 comments