Lesson 17 / 25
CI and Review as the Final Authority
Run tests, scanners and a human review in CI, outside the agent's control.
Checks the agent cannot edit away
Local checks are advisory because an agent can change or skip them. The authoritative checks run in CI on the server, from configuration the agent cannot modify without review: unit tests, linters, secret scanning, dependency and vulnerability scanning, and a required human approval from a code owner. Make sure CI for pull requests from branches or forks does not receive production secrets.
A CI job sketch
Names are illustrative. The point is that these steps run on the server and are required by branch protection.
name: checks
on: pull_request
permissions: { contents: read } # least privilege for the job token
jobs:
verify:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- run: npm ci
- run: npm run lint && npm test
- run: npx gitleaks detect --no-banner # secret scan
- run: npm audit --audit-level=high # dependency scanDo not let the agent approve itself
Require at least one human who is not the author. An agent that opens a pull request and also approves it, or merges with admin rights, defeats the purpose of review.
Quick check: Why are server-side CI checks more trustworthy than local checks?
- Local checks are always wrong
- CI is always faster
- The agent cannot silently modify or skip them
- Local checks cost money
Answer
The agent cannot silently modify or skip them — Checks controlled outside the agent's environment remain valid even if the agent is compromised.