{"id":82933,"date":"2026-09-11T15:01:12","date_gmt":"2026-09-11T09:31:12","guid":{"rendered":"https:\/\/www.tothenew.com\/blog\/?p=82933"},"modified":"2026-09-29T12:17:29","modified_gmt":"2026-09-29T06:47:29","slug":"pr-agent-one-ai-reviewer-centrally-owned-that-cant-weaken-itself","status":"publish","type":"post","link":"https:\/\/www.tothenew.com\/blog\/pr-agent-one-ai-reviewer-centrally-owned-that-cant-weaken-itself\/","title":{"rendered":"AI Code Reviews at Scale: Centralized Rules, Consistent Security"},"content":{"rendered":"<h1><strong>Introduction<\/strong><\/h1>\n<p>A hardcoded key or an unpinned base image slips past a reviewer focused on logic.\u00a0pr-agent\u00a0closes that gap: an internal Action that runs Claude or GPT-5.6, via Bedrock, against every pull request&#8217;s diff, with the review policy owned centrally instead of scattered across every repo that adopts it.<\/p>\n<p>Most teams don&#8217;t lack reviewers who know what to look for \u2014 they lack the bandwidth to apply that judgment on every diff, across a dozen repos and as many stacks, every time. A checklist works until someone skips it under pressure; a linter catches syntax, not a credential pasted in plaintext.\u00a0pr-agent\u00a0isn&#8217;t a stand-in for a reviewer&#8217;s judgment on logic or design \u2014 it&#8217;s insurance that the mechanical stuff never depends on who was free that day.<\/p>\n<ul>\n<li>Two model providers \u2014 Google, Claude or GPT-5.6\u00a0 via Bedrock, swappable with one config value.<\/li>\n<li>Multi-stack by default \u2014 dedicated rules for 12+ languages and stacks, applied only where they show up in the diff.<\/li>\n<li>Custom rules, no fork required \u2014 a repo adds its own styleguide.md on top of the baseline, no changes to the agent itself.<\/li>\n<li>Per-repo control\u00a0\u2014 each repo layers its own rules, or replaces the baseline outright, independent of every other repo.<\/li>\n<\/ul>\n<p>The integration from a consumer repo&#8217;s side is one workflow file:<code><\/code><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-83258\" src=\"https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2026\/09\/Screenshot-2026-09-09-at-5.42.40-PM-300x85.png\" alt=\"Screenshot 2026-09-09 at 5.42.40\u202fPM\" width=\"610\" height=\"173\" srcset=\"https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2026\/09\/Screenshot-2026-09-09-at-5.42.40-PM-300x85.png 300w, https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2026\/09\/Screenshot-2026-09-09-at-5.42.40-PM-1024x290.png 1024w, https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2026\/09\/Screenshot-2026-09-09-at-5.42.40-PM-768x217.png 768w, https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2026\/09\/Screenshot-2026-09-09-at-5.42.40-PM-624x177.png 624w, https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2026\/09\/Screenshot-2026-09-09-at-5.42.40-PM.png 1470w\" sizes=\"auto, (max-width: 610px) 100vw, 610px\" \/><\/p>\n<p>Everything else \u2014 the fork guard, permission checks, language detection, fail-open behavior, and the rules it applies \u2014 lives in\u00a0pr-agent&#8217;s own repo. This post covers how that becomes centrally-owned policy, what the reviewer flags, how to add your own rules, day-to-day commands, and where else it runs.<\/p>\n<h2><strong>Part 1 \u2014 Wired into CI, owned centrally<\/strong><\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-83256\" src=\"https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2026\/09\/architecture-diagram-300x156.png\" alt=\"architecture-diagram\" width=\"567\" height=\"295\" srcset=\"https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2026\/09\/architecture-diagram-300x156.png 300w, https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2026\/09\/architecture-diagram-1024x534.png 1024w, https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2026\/09\/architecture-diagram-768x400.png 768w, https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2026\/09\/architecture-diagram-624x325.png 624w, https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2026\/09\/architecture-diagram.png 1408w\" sizes=\"auto, (max-width: 567px) 100vw, 567px\" \/><\/p>\n<h3>One workflow file, policy owned elsewhere<\/h3>\n<p>config.yaml\u00a0and\u00a0styleguide.md\u00a0are read from\u00a0pr-agent\u00a0itself, not the repo being reviewed \u2014 a repo gets a different file only by deliberately setting\u00a0config-path\u00a0or\u00a0styleguide-path, so a local copy can&#8217;t quietly weaken the review. The baseline rules aren&#8217;t invented from scratch either: Python borrows from Bandit and CERT, Terraform from tfsec and Checkov, one file per stack, sent only when it appears in the diff.<\/p>\n<p>Pair this with an org ruleset that makes the caller workflow required, and a PR whose review never ran simply can&#8217;t merge.<\/p>\n<p><strong>The fork boundary, solved by not being clever<\/strong><\/p>\n<p>Fork PRs aren&#8217;t reviewed \u2014 GitHub withholds secrets from fork-triggered workflows, and the reviewer needs\u00a0BEDROCK_API_KEY. The tempting fix,\u00a0pull_request_target, runs the workflow from the base branch while checking out untrusted head code \u2014 the pattern behind most Actions supply-chain incidents.<\/p>\n<blockquote><p>Deliberately not clever<br \/>\nThe job condition just checks\u00a0head.repo.full_name == github.repository\u00a0and exits otherwise. No secrets reach untrusted code.<\/p><\/blockquote>\n<p><strong>Fail-open, always<\/strong><\/p>\n<p>The review step runs with\u00a0continue-on-error: true; a\u00a0ProviderError\u00a0becomes a notice comment, not a crash. Exit code 2 is reserved for an invalid\u00a0config.yaml. Everything else degrades the same way:<\/p>\n<ul>\n<li>Bedrock unreachable or rate-limited \u2014 a notice explains why.<\/li>\n<li>The model call errors \u2014 same kind of notice.<\/li>\n<li>The Python env fails to install\u00a0\u2014 the step fails, but the workflow stays green.<\/li>\n<\/ul>\n<p>None of these block a merge. A green check doesn&#8217;t prove a review happened look for the summary comment.<\/p>\n<h2>Part 2 \u2014 What the reviewer actually flags<\/h2>\n<h3>Only the languages present in the diff<\/h3>\n<p>The prompt only carries idioms for languages actually present, detected mostly by extension (Dockerfiles, GitHub Actions workflow YAML, and Ansible go by filename or path shape instead). A React PR gets hook guidance, a Go PR gets goroutine guidance \u2014 neither gets the other&#8217;s, and anything undetected simply isn&#8217;t annotated.<\/p>\n<h3>What&#8217;s in scope<\/h3>\n<p>Four focus areas cover most of what the baseline looks for, and each one is a toggle in\u00a0config.yaml&#8217;s\u00a0review.focus:<\/p>\n<ul>\n<li>Secrets and credentials \u2014 passwords, tokens or keys in source or pipeline files.<\/li>\n<li>Containers and infrastructure \u2014 root-run processes, unpinned images, secrets baked into layers.<\/li>\n<li>CI\/CD correctness \u2014 unquoted shell expansions, credentials in logs.<\/li>\n<li>Application correctness\u00a0\u2014 logic errors, resource leaks, query injection<\/li>\n<\/ul>\n<h3>Prompt injection is a finding, not a jailbreak to prevent<\/h3>\n<p>The diff, any comment, and any\u00a0\/ask\u00a0question are untrusted data, never instructions. Code that tries to make the model ignore its rules gets reported as a\u00a0CRITICAL\u00a0finding \u2014 the one place in the config that isn&#8217;t a toggle.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-83260 size-full\" src=\"https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2026\/09\/severity-levels.png\" alt=\"severity-levels\" width=\"1408\" height=\"226\" srcset=\"https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2026\/09\/severity-levels.png 1408w, https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2026\/09\/severity-levels-300x48.png 300w, https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2026\/09\/severity-levels-1024x164.png 1024w, https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2026\/09\/severity-levels-768x123.png 768w, https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2026\/09\/severity-levels-624x100.png 624w\" sizes=\"auto, (max-width: 1408px) 100vw, 1408px\" \/><\/p>\n<h3>What a finding looks like<\/h3>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-83257 size-full\" src=\"https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2026\/09\/finding-mockup.png\" alt=\"finding-mockup\" width=\"1408\" height=\"744\" srcset=\"https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2026\/09\/finding-mockup.png 1408w, https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2026\/09\/finding-mockup-300x159.png 300w, https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2026\/09\/finding-mockup-1024x541.png 1024w, https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2026\/09\/finding-mockup-768x406.png 768w, https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2026\/09\/finding-mockup-624x330.png 624w\" sizes=\"auto, (max-width: 1408px) 100vw, 1408px\" \/><\/p>\n<h3>No database: state lives in a GitHub comment<\/h3>\n<p>The last-reviewed SHA lives as an HTML marker in the bot&#8217;s summary comment. Each push decodes it, diffs the new commits, and skips findings already caught at that line. A force-push that breaks it falls back to a full review \u2014 zero extra infrastructure.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-83261 size-full\" src=\"https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2026\/09\/state-loop-diagram.png\" alt=\"state-loop-diagram\" width=\"1408\" height=\"676\" srcset=\"https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2026\/09\/state-loop-diagram.png 1408w, https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2026\/09\/state-loop-diagram-300x144.png 300w, https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2026\/09\/state-loop-diagram-1024x492.png 1024w, https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2026\/09\/state-loop-diagram-768x369.png 768w, https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2026\/09\/state-loop-diagram-624x300.png 624w\" sizes=\"auto, (max-width: 1408px) 100vw, 1408px\" \/><\/p>\n<h2>Part 3 \u2014 Making it yours: custom rules<\/h2>\n<h3>Add a rule without touching the agent&#8217;s repo<\/h3>\n<p>Drop a\u00a0.github\/pr-agent\/styleguide.md\u00a0into the repo being reviewed and it&#8217;s appended to the baseline on every run \u2014 plain English naming the pattern and why it&#8217;s wrong:<\/p>\n<blockquote><p>.github\/pr-agent\/styleguide.md \u00b7 in the repo being reviewed<br \/>\n## Our team&#8217;s own rules<\/p>\n<p>&#8211; Every `aws_s3_bucket` resource must set `versioning` and<br \/>\n`server_side_encryption_configuration` explicitly \u2014 we&#8217;ve had two<br \/>\nincidents from a bucket that inherited neither.<\/p><\/blockquote>\n<h3>Per-stack rules<\/h3>\n<p>The same model applies one level deeper: a\u00a0.github\/pr-agent\/rules\/terraform.md\u00a0in your repo is appended to the agent&#8217;s Terraform rules \u2014 a team encodes its own footguns per stack without touching the baseline.<\/p>\n<p>That additive model is the default. A rarer lever,\u00a0config-path\/styleguide-path, replaces the policy outright for one repo \u2014 opt-in, for when a repo needs its own policy, not just extra rules.<\/p>\n<h2>Part 4 \u2014 Day to day: commands and providers<\/h2>\n<h2>Slash commands<\/h2>\n<p>Comment on a pull request with any of these and the agent responds directly in the thread:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-83259 size-full\" src=\"https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2026\/09\/Screenshot-2026-09-09-at-6.09.13-PM.png\" alt=\"Screenshot 2026-09-09 at 6.09.13\u202fPM\" width=\"1218\" height=\"714\" srcset=\"https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2026\/09\/Screenshot-2026-09-09-at-6.09.13-PM.png 1218w, https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2026\/09\/Screenshot-2026-09-09-at-6.09.13-PM-300x176.png 300w, https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2026\/09\/Screenshot-2026-09-09-at-6.09.13-PM-1024x600.png 1024w, https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2026\/09\/Screenshot-2026-09-09-at-6.09.13-PM-768x450.png 768w, https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2026\/09\/Screenshot-2026-09-09-at-6.09.13-PM-624x366.png 624w\" sizes=\"auto, (max-width: 1218px) 100vw, 1218px\" \/><\/p>\n<p>Authorization is a live permissions check, not an allow-list, for every command except \/help. Comment text arrives via an environment variable, never interpolated into a shell string.<\/p>\n<p><strong>Who can run them<\/strong><\/p>\n<ul>\n<li>read \u2014 not enough by default.<\/li>\n<li>write \u2014 the default minimum.<\/li>\n<li>maintain \u2014 short of full ownership.<\/li>\n<li>admin\u00a0\u2014 full control.<\/li>\n<\/ul>\n<h3>Two providers, one credential, real retry logic<\/h3>\n<p>AI_PROVIDER\u00a0switches between Claude and GPT-5.6, both via Bedrock on the same\u00a0BEDROCK_API_KEY. Both clients share one retry helper \u2014 specific HTTP statuses and transport errors, with backoff and jitter; anything else fails immediately.<\/p>\n<p><strong>What it won&#8217;t catch<\/strong><\/p>\n<ul>\n<li>Diff-only visibility \u2014 no whole-file or cross-file context.<\/li>\n<li>A comment cap \u2014 max_review_comments, 20 by default.<\/li>\n<li>A severity floor\u00a0\u2014\u00a0comment_severity_threshold, MEDIUM by default; demoted, not dropped.<\/li>\n<\/ul>\n<h2>Part 5 \u2014 Rolling it out, keeping it current<\/h2>\n<h3>Required, not opt-in<\/h3>\n<p>An org-level ruleset makes the caller workflow a required status check across every repo it applies to \u2014 a PR can&#8217;t merge without a run. Voluntary adoption would be the same problem the config split solves: policy that can be skipped isn&#8217;t policy.<\/p>\n<p><strong>Trying it, changing it<\/strong><\/p>\n<p>The agent reviews its own pull requests \u2014 a change to\u00a0.github\/pr-agent\u00a0is reviewed by the previous version of itself. Consumers pin a release tag; the\u00a0uses:\u00a0reference bumps in the same PR, or a tagged workflow runs an untagged action.<\/p>\n<h2>Conclusion<\/h2>\n<p>Individually, none of these pieces are exotic. Together they guarantee one property: no repo&#8217;s review is weaker than any other&#8217;s, and none can opt out while still showing green.<\/p>\n<ul>\n<li>Central ownership \u2014 a repo can add to the policy, not replace it, unless it opts in.<\/li>\n<li>Fork-safe by construction \u2014 a same-repo check, not a secrets trick.<\/li>\n<li>Fails open, never silently \u2014 never blocks a merge, always says so.<\/li>\n<li>No external state \u2014 review rides inside the PR&#8217;s own comment.<\/li>\n<li>Required, not opt-in\u00a0\u2014 an org ruleset, not a voluntary add.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Introduction A hardcoded key or an unpinned base image slips past a reviewer focused on logic.\u00a0pr-agent\u00a0closes that gap: an internal Action that runs Claude or GPT-5.6, via Bedrock, against every pull request&#8217;s diff, with the review policy owned centrally instead of scattered across every repo that adopts it. Most teams don&#8217;t lack reviewers who know [&hellip;]<\/p>\n","protected":false},"author":1719,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"iawp_total_views":2,"footnotes":""},"categories":[2348],"tags":[4782,1853,8984],"class_list":["post-82933","post","type-post","status-publish","format-standard","hentry","category-devops-technology","tag-ai","tag-automation","tag-pr"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"Introduction A hardcoded key or an unpinned base image slips past a reviewer focused on logic. pr-agent closes that gap: an internal Action that runs Claude or GPT-5.6, via Bedrock, against every pull request&#039;s diff, with the review policy owned centrally instead of scattered across every repo that adopts it. Most teams don&#039;t lack reviewers who know\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Saif Ahmad\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.tothenew.com\/blog\/pr-agent-one-ai-reviewer-centrally-owned-that-cant-weaken-itself\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"TO THE NEW BLOG\" \/>\n\t\t<meta property=\"og:type\" content=\"blog\" \/>\n\t\t<meta property=\"og:title\" content=\"AI Code Reviews at Scale: Centralized Rules, Consistent Security | TO THE NEW Blog\" \/>\n\t\t<meta property=\"og:description\" content=\"Introduction A hardcoded key or an unpinned base image slips past a reviewer focused on logic. pr-agent closes that gap: an internal Action that runs Claude or GPT-5.6, via Bedrock, against every pull request&#039;s diff, with the review policy owned centrally instead of scattered across every repo that adopts it. Most teams don&#039;t lack reviewers who know\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.tothenew.com\/blog\/pr-agent-one-ai-reviewer-centrally-owned-that-cant-weaken-itself\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/www.tothenew.com\/blog\/wp-content\/themes\/ttn\/images\/social-logo.png\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/www.tothenew.com\/blog\/wp-content\/themes\/ttn\/images\/social-logo.png\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@tothenew\" \/>\n\t\t<meta name=\"twitter:title\" content=\"AI Code Reviews at Scale: Centralized Rules, Consistent Security | TO THE NEW Blog\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Introduction A hardcoded key or an unpinned base image slips past a reviewer focused on logic. pr-agent closes that gap: an internal Action that runs Claude or GPT-5.6, via Bedrock, against every pull request&#039;s diff, with the review policy owned centrally instead of scattered across every repo that adopts it. Most teams don&#039;t lack reviewers who know\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/www.tothenew.com\/blog\/wp-content\/themes\/ttn\/images\/social-logo.png\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/pr-agent-one-ai-reviewer-centrally-owned-that-cant-weaken-itself\\\/#article\",\"name\":\"AI Code Reviews at Scale: Centralized Rules, Consistent Security | TO THE NEW Blog\",\"headline\":\"AI Code Reviews at Scale: Centralized Rules, Consistent Security\",\"author\":{\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/author\\\/saif-ahmad\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/wp-ttn-blog\\\/uploads\\\/2026\\\/09\\\/Screenshot-2026-09-09-at-5.42.40-PM-300x85.png\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/pr-agent-one-ai-reviewer-centrally-owned-that-cant-weaken-itself\\\/#articleImage\"},\"datePublished\":\"2026-09-11T15:01:12+05:30\",\"dateModified\":\"2026-09-29T12:17:29+05:30\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/pr-agent-one-ai-reviewer-centrally-owned-that-cant-weaken-itself\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/pr-agent-one-ai-reviewer-centrally-owned-that-cant-weaken-itself\\\/#webpage\"},\"articleSection\":\"DevOps, AI, Automation, PR\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/pr-agent-one-ai-reviewer-centrally-owned-that-cant-weaken-itself\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.tothenew.com\\\/blog\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/category\\\/devops-technology\\\/#listItem\",\"name\":\"DevOps\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/category\\\/devops-technology\\\/#listItem\",\"position\":2,\"name\":\"DevOps\",\"item\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/category\\\/devops-technology\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/pr-agent-one-ai-reviewer-centrally-owned-that-cant-weaken-itself\\\/#listItem\",\"name\":\"AI Code Reviews at Scale: Centralized Rules, Consistent Security\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/pr-agent-one-ai-reviewer-centrally-owned-that-cant-weaken-itself\\\/#listItem\",\"position\":3,\"name\":\"AI Code Reviews at Scale: Centralized Rules, Consistent Security\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/category\\\/devops-technology\\\/#listItem\",\"name\":\"DevOps\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/#organization\",\"name\":\"TO THE NEW Blog\",\"url\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/author\\\/saif-ahmad\\\/#author\",\"url\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/author\\\/saif-ahmad\\\/\",\"name\":\"Saif Ahmad\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/pr-agent-one-ai-reviewer-centrally-owned-that-cant-weaken-itself\\\/#authorImage\",\"url\":\"https:\\\/\\\/newersworld-sf-static.tothenew.net\\\/prod\\\/profilePicFolder\\\/6d7b39d4-2956-4c96-bbfc-d3d04b4d31a1_5084-Saif-Ahmad-PROFILEPICTURE.jpeg\",\"width\":96,\"height\":96,\"caption\":\"Saif Ahmad\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/pr-agent-one-ai-reviewer-centrally-owned-that-cant-weaken-itself\\\/#webpage\",\"url\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/pr-agent-one-ai-reviewer-centrally-owned-that-cant-weaken-itself\\\/\",\"name\":\"AI Code Reviews at Scale: Centralized Rules, Consistent Security | TO THE NEW Blog\",\"description\":\"Introduction A hardcoded key or an unpinned base image slips past a reviewer focused on logic. pr-agent closes that gap: an internal Action that runs Claude or GPT-5.6, via Bedrock, against every pull request's diff, with the review policy owned centrally instead of scattered across every repo that adopts it. Most teams don't lack reviewers who know\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/pr-agent-one-ai-reviewer-centrally-owned-that-cant-weaken-itself\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/author\\\/saif-ahmad\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/author\\\/saif-ahmad\\\/#author\"},\"datePublished\":\"2026-09-11T15:01:12+05:30\",\"dateModified\":\"2026-09-29T12:17:29+05:30\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/\",\"name\":\"TO THE NEW Blog\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"AI Code Reviews at Scale: Centralized Rules, Consistent Security | TO THE NEW Blog","description":"Introduction A hardcoded key or an unpinned base image slips past a reviewer focused on logic. pr-agent closes that gap: an internal Action that runs Claude or GPT-5.6, via Bedrock, against every pull request's diff, with the review policy owned centrally instead of scattered across every repo that adopts it. Most teams don't lack reviewers who know","canonical_url":"https:\/\/www.tothenew.com\/blog\/pr-agent-one-ai-reviewer-centrally-owned-that-cant-weaken-itself\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.tothenew.com\/blog\/pr-agent-one-ai-reviewer-centrally-owned-that-cant-weaken-itself\/#article","name":"AI Code Reviews at Scale: Centralized Rules, Consistent Security | TO THE NEW Blog","headline":"AI Code Reviews at Scale: Centralized Rules, Consistent Security","author":{"@id":"https:\/\/www.tothenew.com\/blog\/author\/saif-ahmad\/#author"},"publisher":{"@id":"https:\/\/www.tothenew.com\/blog\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2026\/09\/Screenshot-2026-09-09-at-5.42.40-PM-300x85.png","@id":"https:\/\/www.tothenew.com\/blog\/pr-agent-one-ai-reviewer-centrally-owned-that-cant-weaken-itself\/#articleImage"},"datePublished":"2026-09-11T15:01:12+05:30","dateModified":"2026-09-29T12:17:29+05:30","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/www.tothenew.com\/blog\/pr-agent-one-ai-reviewer-centrally-owned-that-cant-weaken-itself\/#webpage"},"isPartOf":{"@id":"https:\/\/www.tothenew.com\/blog\/pr-agent-one-ai-reviewer-centrally-owned-that-cant-weaken-itself\/#webpage"},"articleSection":"DevOps, AI, Automation, PR"},{"@type":"BreadcrumbList","@id":"https:\/\/www.tothenew.com\/blog\/pr-agent-one-ai-reviewer-centrally-owned-that-cant-weaken-itself\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.tothenew.com\/blog#listItem","position":1,"name":"Home","item":"https:\/\/www.tothenew.com\/blog","nextItem":{"@type":"ListItem","@id":"https:\/\/www.tothenew.com\/blog\/category\/devops-technology\/#listItem","name":"DevOps"}},{"@type":"ListItem","@id":"https:\/\/www.tothenew.com\/blog\/category\/devops-technology\/#listItem","position":2,"name":"DevOps","item":"https:\/\/www.tothenew.com\/blog\/category\/devops-technology\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.tothenew.com\/blog\/pr-agent-one-ai-reviewer-centrally-owned-that-cant-weaken-itself\/#listItem","name":"AI Code Reviews at Scale: Centralized Rules, Consistent Security"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.tothenew.com\/blog#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/www.tothenew.com\/blog\/pr-agent-one-ai-reviewer-centrally-owned-that-cant-weaken-itself\/#listItem","position":3,"name":"AI Code Reviews at Scale: Centralized Rules, Consistent Security","previousItem":{"@type":"ListItem","@id":"https:\/\/www.tothenew.com\/blog\/category\/devops-technology\/#listItem","name":"DevOps"}}]},{"@type":"Organization","@id":"https:\/\/www.tothenew.com\/blog\/#organization","name":"TO THE NEW Blog","url":"https:\/\/www.tothenew.com\/blog\/"},{"@type":"Person","@id":"https:\/\/www.tothenew.com\/blog\/author\/saif-ahmad\/#author","url":"https:\/\/www.tothenew.com\/blog\/author\/saif-ahmad\/","name":"Saif Ahmad","image":{"@type":"ImageObject","@id":"https:\/\/www.tothenew.com\/blog\/pr-agent-one-ai-reviewer-centrally-owned-that-cant-weaken-itself\/#authorImage","url":"https:\/\/newersworld-sf-static.tothenew.net\/prod\/profilePicFolder\/6d7b39d4-2956-4c96-bbfc-d3d04b4d31a1_5084-Saif-Ahmad-PROFILEPICTURE.jpeg","width":96,"height":96,"caption":"Saif Ahmad"}},{"@type":"WebPage","@id":"https:\/\/www.tothenew.com\/blog\/pr-agent-one-ai-reviewer-centrally-owned-that-cant-weaken-itself\/#webpage","url":"https:\/\/www.tothenew.com\/blog\/pr-agent-one-ai-reviewer-centrally-owned-that-cant-weaken-itself\/","name":"AI Code Reviews at Scale: Centralized Rules, Consistent Security | TO THE NEW Blog","description":"Introduction A hardcoded key or an unpinned base image slips past a reviewer focused on logic. pr-agent closes that gap: an internal Action that runs Claude or GPT-5.6, via Bedrock, against every pull request's diff, with the review policy owned centrally instead of scattered across every repo that adopts it. Most teams don't lack reviewers who know","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.tothenew.com\/blog\/#website"},"breadcrumb":{"@id":"https:\/\/www.tothenew.com\/blog\/pr-agent-one-ai-reviewer-centrally-owned-that-cant-weaken-itself\/#breadcrumblist"},"author":{"@id":"https:\/\/www.tothenew.com\/blog\/author\/saif-ahmad\/#author"},"creator":{"@id":"https:\/\/www.tothenew.com\/blog\/author\/saif-ahmad\/#author"},"datePublished":"2026-09-11T15:01:12+05:30","dateModified":"2026-09-29T12:17:29+05:30"},{"@type":"WebSite","@id":"https:\/\/www.tothenew.com\/blog\/#website","url":"https:\/\/www.tothenew.com\/blog\/","name":"TO THE NEW Blog","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.tothenew.com\/blog\/#organization"}}]},"og:locale":"en_US","og:site_name":"TO THE NEW BLOG","og:type":"blog","og:title":"AI Code Reviews at Scale: Centralized Rules, Consistent Security | TO THE NEW Blog","og:description":"Introduction A hardcoded key or an unpinned base image slips past a reviewer focused on logic. pr-agent closes that gap: an internal Action that runs Claude or GPT-5.6, via Bedrock, against every pull request's diff, with the review policy owned centrally instead of scattered across every repo that adopts it. Most teams don't lack reviewers who know","og:url":"https:\/\/www.tothenew.com\/blog\/pr-agent-one-ai-reviewer-centrally-owned-that-cant-weaken-itself\/","og:image":"https:\/\/www.tothenew.com\/blog\/wp-content\/themes\/ttn\/images\/social-logo.png","og:image:secure_url":"https:\/\/www.tothenew.com\/blog\/wp-content\/themes\/ttn\/images\/social-logo.png","twitter:card":"summary","twitter:site":"@tothenew","twitter:title":"AI Code Reviews at Scale: Centralized Rules, Consistent Security | TO THE NEW Blog","twitter:description":"Introduction A hardcoded key or an unpinned base image slips past a reviewer focused on logic. pr-agent closes that gap: an internal Action that runs Claude or GPT-5.6, via Bedrock, against every pull request's diff, with the review policy owned centrally instead of scattered across every repo that adopts it. Most teams don't lack reviewers who know","twitter:image":"https:\/\/www.tothenew.com\/blog\/wp-content\/themes\/ttn\/images\/social-logo.png"},"aioseo_meta_data":{"post_id":"82933","title":null,"description":null,"keywords":null,"keyphrases":{"focus":{"keyphrase":"","score":0,"analysis":{"keyphraseInTitle":{"score":0,"maxScore":9,"error":1}}},"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"Article","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"limit_modified_date":false,"created":"2026-09-09 12:13:20","updated":"2026-09-29 06:47:31","focus_keyword":null,"additional_keywords":null,"truseo_locale":null,"ai":{"faqs":[],"keyPoints":[],"schemas":[],"titles":[],"descriptions":[],"socialPosts":{"email":{"subject":"","preview":"","content":""},"linkedin":[],"twitter":[],"facebook":[],"instagram":[]}},"breadcrumb_settings":null,"seo_analyzer_scan_date":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/www.tothenew.com\/blog\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/www.tothenew.com\/blog\/category\/devops-technology\/\" title=\"DevOps\">DevOps<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tAI Code Reviews at Scale: Centralized Rules, Consistent Security\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/www.tothenew.com\/blog"},{"label":"DevOps","link":"https:\/\/www.tothenew.com\/blog\/category\/devops-technology\/"},{"label":"AI Code Reviews at Scale: Centralized Rules, Consistent Security","link":"https:\/\/www.tothenew.com\/blog\/pr-agent-one-ai-reviewer-centrally-owned-that-cant-weaken-itself\/"}],"_links":{"self":[{"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/posts\/82933","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/users\/1719"}],"replies":[{"embeddable":true,"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/comments?post=82933"}],"version-history":[{"count":10,"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/posts\/82933\/revisions"}],"predecessor-version":[{"id":83758,"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/posts\/82933\/revisions\/83758"}],"wp:attachment":[{"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/media?parent=82933"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/categories?post=82933"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/tags?post=82933"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}