Code review in a production application
A pull request changes authentication middleware. The review service sends the diff, nearby functions, repository security rules, and the changed-line map to codex-auto-review. The model must return only findings that identify a concrete failure path.
The service rejects comments without a file, changed line, severity, evidence, and repair. Clean pull requests are part of the evaluation set, so producing more comments is not treated as better review.
