Evidence-First Review
Demonstrate a defect through its trigger, path and consequence.
These examples and illustrative results are independently authored teaching materials, not measured model results.
Use case
Review a teaching profile path: getUser returns null on cache miss, then its caller reads user.email. Establish reachability rather than reporting a defect merely because a value is nullable.
Mechanism
Read return definitions, callers and surrounding guards with input/state and version. Trace whether a miss reaches dereferencing and whether framework/types handle it. Reproduce with a cache-miss fixture when possible; otherwise label code inference. Report citations, trigger, consequence, why guards fail and a scoped remedy, rating actual impact. Unconfirmed paths remain gaps rather than certain defects.
Bad example
A missing null check violates best practice. Add validation and label it highest severity without reading callers.
Good example
Inspect the actual getUser miss→profile email path. Cite null return and dereference, check early-exit guards, and test TypeError with a miss input or explicitly report static inference only. Name affected entry points and a remedy rather than a rule label.
Why the change matters
Triggers and propagation explain failure and eliminate false positives already guarded upstream. Evidence-bound impact lets the author reproduce instead of debating abstract conventions.
Observable expectation
The unguarded teaching path has citations for null return and dereference. Adding a caller miss branch invalidates the original finding. Unexecuted fixtures support an expected TypeError, not an invented stack trace. A guarded path may yield zero findings.
Limits
Generated fields cannot be disproved by absent literal text. Code inference is not an observed incident; unreachable triggers and unknown contracts need caveats. Source-backed confidence is not calibrated probability, and review value does not require manufactured findings.
Sources and evidence
- garrytan/gstack · Pre-emit verification gate
File at this versionf30b7b788a21 - affaan-m/ECC · Pre-report gate, severity proof and valid zero findings
File at this versionef648e01899b