Lesson 17 / 25

CI and Review as the Final Authority

Run tests, scanners and a human review in CI, outside the agent's control.

Checks the agent cannot edit away

Local checks are advisory because an agent can change or skip them. The authoritative checks run in CI on the server, from configuration the agent cannot modify without review: unit tests, linters, secret scanning, dependency and vulnerability scanning, and a required human approval from a code owner. Make sure CI for pull requests from branches or forks does not receive production secrets.

A CI job sketch

Names are illustrative. The point is that these steps run on the server and are required by branch protection.

name: checks
on: pull_request
permissions: { contents: read }      # least privilege for the job token
jobs:
  verify:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - run: npm ci
      - run: npm run lint && npm test
      - run: npx gitleaks detect --no-banner      # secret scan
      - run: npm audit --audit-level=high         # dependency scan

Do not let the agent approve itself

Require at least one human who is not the author. An agent that opens a pull request and also approves it, or merges with admin rights, defeats the purpose of review.

Quick check: Why are server-side CI checks more trustworthy than local checks?

  • Local checks are always wrong
  • CI is always faster
  • The agent cannot silently modify or skip them
  • Local checks cost money
Answer

The agent cannot silently modify or skip them — Checks controlled outside the agent's environment remain valid even if the agent is compromised.