16 karma · joined November 4, 2025
If you're a dev who cares about this, the new quality and security enforcement infrastructure needs to happen alongside the agents, locally. The tools to address this are still in early stages - meaning, a tool that isn't the same model reviewing itself - but they're starting to surface and it's worth keeping an eye on them.
The autocomplete stage is basically a throwback to 2024 and is mostly harmless - the traditional SAST and code review practices handle it.
Prompting agents to build whole features, which is where most people are today, comes with some security and maintainability concerns, but there are already solutions in place.
The problem is that most teams are also starting to explore loop engineering with autonomous agents. This currently has no guardrails in place, which is a recipe for disaster, as the video explains.
If you're exploring loop engineering, this is for you.
The latest version is v0.27.0
> npm install -g @codacy/verity-cli
> verity init
Let me know if you have any questions!
>But as AI generates more of the code, the industry will likely move toward more radical review models.
>>Quit dancing around it and just advocate pushing to main. The PR model is to have a quality gate.
The dancing is IMO a reasonable analysis of the state of the code review today. Yes, there are systems in the works but today there isn't yet a good enough system of automated checks to simply let code through. Because then this happens https://pages.faros.ai/hubfs/AI_Engineering_Report_2026_The_...
The goal with the article is to explain what tools can be employed to tackle the PR bottleneck and where humans are still needed - at this point in time. Code quality and security platforms like Codacy (here's the service) can automate away many baseline checks (SAST, test coverage, complexity, duplication, linters, etc). This provides deterministic analysis that is the same every time, unlike pure AI code reviewers. But there's very much still room for AI-assisted reviews. AI is very good at identifying what has changed, grouping findings by severity and helping the human reviewer focus their attention. After these 2 passes, human attention can be reserved for the important judgement calls. "Human reviewers concentrate on judgment rather than scanning for issues that tools can detect consistently."
Codacy does both layers, the deterministic checks that have to be repeatable and auditable, and the AI on top. This cuts review time without lowering coding standards.