A worked example, rendered from real sample data. Sign in to run the tool on your own input.
diff --git a/src/auth/session.ts b/src/auth/session.ts
--- a/src/auth/session.ts
+++ b/src/auth/session.ts
@@ -12,7 +12,11 @@ export function createSession(userId: string) {
const token = randomBytes(32).toString("hex");
- return { token };
+ console.log("new session", userId, token);
+ const apiKey = "sk_live_9f2a71c4b8de3315";
+ return { token, userId, apiKey };
}
diff --git a/package.json b/package.json
--- a/package.json
+++ b/package.json
@@ -8,6 +8,7 @@
"dependencies": {
+ "jsonwebtoken": "^9.0.2",
"react": "^19.0.0"
}═══ Change Summary ═══
Files changed: 2
Lines: +4 / -1 (net +3)
Files worth reading closely: 2
Largest file: src/auth/session.ts
What changed: dependencies, security-sensitive code, configuration
Review profile: standard
✓ 5 changed lines is a reviewable size
ℹ This is a checklist built by pattern-matching the diff you pasted. It does not understand your code, it is not an AI review, and it never replaces reading the change.
═══ Pattern checks on added lines ═══
⚠ debug-log: 1 occurrence — Debug logging left in. Remove it or route it through the logger.
✗ hardcoded-secret: 1 occurrence — This looks like a credential committed in plain text. Rotate it and move it to a secret store.
═══ Review checklist ═══
── Always ──
• Does the PR description say why, not just what? 2 files, +4/-1.
• Can this change be reverted on its own, or does it depend on an out-of-band step?
• Is anything here better as a separate PR?
── Tests ──
• ✗ No test file appears in this diff. Ask what would have caught this bug or proved this feature.
• If the change is genuinely untestable, is that worth a note in the description?
── Dependencies ──
• Which dependency changed and why — is it a direct need or an incidental bump?
• Does the lockfile change match the manifest change?
• Any licence change in a new transitive dependency?
• Does the new version have a changelog entry that affects this codebase?
── Security-sensitive paths ──
• Touched: src/auth/session.ts
• Is every new input validated on the server, not only in the client?
• Does authorisation get checked on the new path, not just authenticati
…
Build a reviewer checklist and draft comments from a unified diff you paste (static analysis, not an AI review). Part of the DevTools Surf developer suite. Browse more tools in the DevOps / CI-CD collection.