Manual Threat Thinking Still Matters
Explain why AI code review does not replace manual security reasoning.
Reframe: AI can spot patterns; humans must reason about abuse. Start With Control For each input, identify who controls it. User-controlled values, third-party callbacks, queue messages, and headers deserve more suspicion than internal constants. Cross the Boundary Find where data or authority crosses a trust boundary: public to internal, tenant A to tenant B, user to admin, unauthenticated to authenticated, low privilege to high privilege. Challenge the Happy Path Ask what happens when the caller lies, repeats, races, omits, or replays. If the answer depends on a business rule the model was not given, AI silence is weak evidence.
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in