Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
IT Security NachrichtenOnePlus/OxygenOS: Schad-App erhält Root-Zugriff ohne Berechtigungen(24.09.2026 um 23:38 Uhr)
•
IT Security NachrichtenRyuk Member Karen Vardanyan Sentenced to Two Years in U.S. Prison(24.09.2026 um 22:50 Uhr)
•••••
Hacking & PentestingRyuk Member Karen Vardanyan Sentenced to Two Years in U.S. Prison(24.09.2026 um 22:50 Uhr)
•
AI & KI NachrichtenWhy the U.N. Still Matters(24.09.2026 um 23:00 Uhr)
•••
IT Security NachrichtenOnePlus/OxygenOS: Schad-App erhält Root-Zugriff ohne Berechtigungen(24.09.2026 um 23:38 Uhr)
•
IT Security NachrichtenRyuk Member Karen Vardanyan Sentenced to Two Years in U.S. Prison(24.09.2026 um 22:50 Uhr)
•••••
Hacking & PentestingRyuk Member Karen Vardanyan Sentenced to Two Years in U.S. Prison(24.09.2026 um 22:50 Uhr)
•
AI & KI NachrichtenWhy the U.N. Still Matters(24.09.2026 um 23:00 Uhr)
•••
Intelligence View
⚡ tsecurity.de Intelligence

GitHub Copilot Completes a Real Code Review (Claude Sonnet 4.5)

One of the more interesting experiments I recently ran was asking GitHub Copilot to perform a full code review on a .NET application that it had also helped rewrite. The original project was written in 2013. The application still worked,…

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!

One of the more interesting experiments I recently ran was asking GitHub Copilot to perform a full code review on a .NET application that it had also helped rewrite.



The original project was written in 2013. The application still worked, but the codebase had accumulated a lot of technical debt over the years.



Rather than trying to gradually refactor it, I decided to do a complete rewrite with Copilot’s help using modern conventions in the .NET ecosystem.



Once the rewrite was finished, I wanted to answer a simple question:



How useful is an AI-generated code review on a real-world project?



So I asked Copilot to review:




  • The original legacy codebase

  • The new rewritten solution



The results were interesting.









Watch Full Video













Starting With a Simple AI Code Review



The easiest way to run an AI code review is something like this:




Perform a code review on this project.






Copilot will usually return a fairly useful response that includes things like:




  • Naming issues

  • Readability improvements

  • Basic design observations

  • Possible refactoring opportunities



But there is a problem with this approach.



The review tends to focus mostly on surface-level code quality.



In my legacy project, the biggest issues weren’t small code smells. The real problems were architectural.



For example:




  • Many classes were static

  • Several classes simply passed calls directly to the data access layer

  • Domain logic and database logic were mixed together

  • The solution had no automated tests



The initial open-ended review mentioned some issues, but it completely missed the severity of the architectural problems.











The Other Problem: AI Doesn’t Know Your Standards



Another issue with AI reviews is that the model does not know your team conventions.



Every system has different priorities.



Some systems are mostly CRUD applications where fast queries are the most important factor.



Other systems might be financial or analytical platforms where things like:




  • deterministic calculations

  • validation rules

  • extensive unit testing



are critical.



Without guidance, Copilot evaluates code using generic best practices, not the standards that actually matter for your project.









AI Reviews Also Tend to Be Polite



Another thing I noticed is that AI-generated reviews tend to be very diplomatic.



They rarely say something like:




This architecture is fundamentally broken.




Instead they produce much softer language.



In fact, the first open-ended review Copilot generated described the legacy codebase as:




“A well-structured lottery simulation system with clear domain modeling and separation of concerns.”




That assessment was far more positive than reality.









Giving AI a Code Review Scorecard



To get a more realistic review, I gave Copilot a structured review scorecard.



Instead of asking for a general opinion, the AI had to evaluate the project across several weighted categories.



For example:




























Category Weight
Architecture High
Testing 20%
Programming practices 15%
Maintainability Medium


Interestingly, in this scoring model writing code itself only accounts for about 15% of the total score.



That reflects something many experienced developers already know:




Software quality is determined far more by architecture and testing than by individual lines of code.












The Result: Reviewing the Legacy Code



Once Copilot evaluated the legacy project using the scorecard, the results were dramatically different.



The system scored:



15 / 100



The review highlighted several major issues:




  • No clear architectural structure

  • Tight coupling between components

  • No automated tests

  • Poor separation of responsibilities



The final recommendation from the AI was very direct:



Do not attempt to fix this system incrementally.



Instead:




  • Treat the codebase as reference material

  • Perform a full rewrite

  • Avoid investing time into patching severe technical debt



This was the type of honest assessment that the simple open-ended review failed to produce.









Reviewing the Rewritten Version



After several days of work — with Copilot helping with much of the code — I ran the same structured review on the new version.



The rewritten solution followed a structure that most developers familiar with the .NET ecosystem would recognize:




  • clear project separation

  • cleaner domain organization

  • proper data access layers

  • improved maintainability



The application itself is a simple lottery simulation tool that can generate numbers based on historical results and simulate outcomes.



And like most lottery simulations, it demonstrates one consistent result:



Even when simulated millions of times, the expected outcome is still a loss.











An Interesting AI Behavior



When I ran the review on the new codebase, Copilot generated a detailed report but did not include the final score.



I had to prompt it again to output the result using the same scorecard format.



This highlights something important about working with AI systems.



AI responses are not fully deterministic.



Even when using the same prompts and templates, the output may vary slightly because the model is generating responses rather than executing fixed instructions.



If the responses were identical every time, it would behave more like a script than an AI model.









Key Takeaways



Using AI for code reviews can be extremely useful, but it works best when used correctly.






1. AI Needs Structure



Without a structured review framework, AI reviews will stay fairly shallow.



Providing guidelines dramatically improves the analysis.









2. AI Defaults to Being Polite



If you want honest feedback, you need to force the AI to follow strict evaluation criteria.



Otherwise the review may sound overly positive.









3. AI Is Not Deterministic



Even with identical prompts, AI responses may vary.



This is normal behavior for generative AI systems.









4. AI Works Best as an Engineering Assistant



AI tools can greatly accelerate tasks like:




  • code reviews

  • refactoring analysis

  • technical debt assessment



But they still work best when combined with human engineering judgment.











Final Thoughts



Using Copilot to both rewrite and review a codebase turned out to be a fascinating experiment.



The biggest lesson was simple:



AI becomes much more powerful when you give it structure.



A simple prompt produces interesting feedback.



A structured framework produces actionable engineering insight.









📚 Watch the Full Series



Episode 1: GitHub Copilot AI Code Review - Can AI Understand Legacy .NET Code?

https://youtu.be/P26t5EVz70U



Episode 2: Creating .NET Projects and Solution Structure

https://youtu.be/Vf0yULOHY3I



Episode 3: Legacy Code Rewrite - Random Number Generator

https://youtu.be/6DuaW9VjQa8



Episode 4: Working Without Agent Skills in Visual Studio 2026

https://youtu.be/dznUGMNhqSU



Episode 5: Vibe Coding Razor Pages

https://youtu.be/sQdByQML_w8



➡️ Episode 6: Code Review (this article)

https://youtu.be/omDvFGu8Vtc

SOC Incident Playbook: Remote Code Execution (RCE) Defense
Syntax validiert (0 Fehler)
title: Detect Exploitation - GitHub Copilot Completes a Real Code Review (Claude Sonnet 4.5)
id: b4ef8e65-2e8c-4af7-935b-e77608d80a95
status: experimental
description: Automatisch generierte SIEM-Erkennungsregel basierend auf CTI Intelligence
references:
  - https://tsecurity.de/
author: iShareStuff CTI Automated Detection Engine
date: 2026-09-24
logsource:
  category: network_connection
  product: any
detection:
  selection:
      CommandLine|contains:
        - 'exploit'
  condition: selection
falsepositives:
  - Legitime administrative Zugriffe oder Penetrationstests
level: high
tags:
  - attack.initial_access
Syntax validiert (0 Fehler)
rule CTI_Threat_Indicator {
    meta:
        author = "iShareStuff CTI Automated Detection Engine"
        date = "2026-09-24"
        description = "YARA Signature for "
    strings:
        $str = "GitHub Copilot Completes a Rea" ascii wide
    condition:
        any of them
}
Syntax validiert (0 Fehler)
index=security sourcetype IN ("cisco:asa", "pan:traffic", "zeek_conn", "suricata", "WinEventLog:Security")
("GitHub Copilot Completes a Real Code Rev")
| stats count earliest(_time) as first_seen latest(_time) as last_seen by src_ip, dest_ip, dest_host, signature
| eval first_seen=strftime(first_seen, "%Y-%m-%d %H:%M:%S"), last_seen=strftime(last_seen, "%Y-%m-%d %H:%M:%S")
| sort - count
Syntax validiert (0 Fehler)
message: "*GitHub Copilot Completes a Real Code Rev*"
Syntax validiert (0 Fehler)
CommonSecurityLog
| where Message has "GitHub Copilot Completes a Real Code Rev"
| summarize EventCount = count(), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated) by SourceIP, DestinationIP, DestinationPort, Activity
| extend DetectionRule = "iShareStuff-CTI-Compiled"
| sort by EventCount desc
🎯
MITRE ATT&CK Matrix Navigator 14 Taktiken
Reconnaissance
-
Resource Development
-
Initial Access
Execution
Persistence
-
Privilege Escalation
Defense Evasion
Credential Access
-
Discovery
-
Lateral Movement
-
Collection
-
Command and Control
Exfiltration
-
Impact
tsecurity.de Cognitive Threat RAG
Fokus-Vektor:

Kognitive Analyse für identifizierte Bedrohung: Erhöhte Bedrohungslage im Bereich GitHub Copilot Completes a Real Code Rev.... Basierend auf 368k Vektor-Korrelationen werden sofortige Isolationsmaßnahmen für betroffene Endpunkte empfohlen.

🛡️ Angriffsfläche & Exposure

Netzwerk/Remote-Zugriff ohne Vorauthentifizierung möglich.

⚡ Empfohlene Sofortmaßnahmen
  • 1. Perimeter-Inspektion: Relevante Portfreigaben und exponierte Endpunkte unverzüglich scannen.
  • 2. Patch-Applikation: Hersteller-Hotfix einspielen oder betroffene Daemons in isolierte DMZ-Segmente überführen.
  • 3. Telemetrie & EDR-Alerts: Prozessaufrufe und Child-Processes auf anomale Shell-Spawns überwachen.
🔗 Semantisch verwandte Zero-Days MariaDB 11.7 VEC
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten GitHub Copilot Completes a Real Code Review (Claude Sonnet 4.5)

Thematisch verwandte Begriffe: GitHub, Copilot, Completes, Real · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-81473 | Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an …
Advisory →
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel • Rechts: nächster Artikel • unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel TTP ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...
↗ Original-Quelle