01 · 12 min · 2026-09-09
Reviewing AI-Generated Code: Why the Checklist Is Not Enough
AI code fails across files, not inside diffs. Why pull-request review structurally cannot catch it, and the four repository-level measurements that can.
What to check before an AI-generated codebase carries real users: where generated code leaves gaps, how they leak data, and whether the app is ready to scale.
3 guides · updated 13 September 2026
01 · 12 min · 2026-09-09
AI code fails across files, not inside diffs. Why pull-request review structurally cannot catch it, and the four repository-level measurements that can.
02 · 12 min · 2026-09-11
One in ten AI-generated production apps in a 2025 disclosure shipped without row-level security. The cause is not the tool - it is a boundary nobody was asked to define.
03 · 11 min · 2026-09-11
Four measurements you can run on your own Supabase project this afternoon, with the thresholds that separate a platform you can build on from one you should stop building on.
These write-ups come out of production systems rather than reading. If you are building in this area, here is how I work on it — and the benchmark results are the numbers behind the claims, including the ones that look bad.