# Review AI-generated code

Taiga Learning · Worksheet
https://taiga.training/en/lessons/review-ai-code/

Use fictional or approved information. Do not put secrets in this worksheet.

## Learning objectives
- Review behavior and authority before style.
- Identify a missing authorization check in a small example.
- Separate a generated summary from verified evidence.

## Exercise
Open the code review exercise in the practice lab. Identify the actor, requested resource, and trusted organization boundary. Then inspect a real small PR with the same method. Use only code you are authorized to review.

## Your response
- Scenario and scope:
- Assumptions and open questions:
- Proposed answer or decision, with reasons:

## Verify your response
| Claim or criterion | Evidence or test | Result or gap | Owner |
| --- | --- | --- | --- |
| | | | |
| | | | |
| | | | |

## Next action
- Action, owner, and date:
- When will you review this response?

## Principle to retain
Review the final diff and the relevant checks. The author of the code does not change the release responsibility.

## Sources
- [Google Engineering Practices: Code review](https://google.github.io/eng-practices/review/reviewer/looking-for.html)
- [OWASP: Authorization Cheat Sheet](https://cheatsheetseries.owasp.org/cheatsheets/Authorization_Cheat_Sheet.html)

This worksheet supports learning. Completing it does not itself authorize a production change.
