I've been working a lot on building a system like this personally over the last few months - Cloudflare are either not stating or missing one important issue. While they are doing loop improvement on the Standards themselves, they are forgetting to do improvement on the model. So in their language, they are improving the Codex, but they are NOT improving the reviewer and they need to close that loop.
Great bit of work, I rate it up there with their thoughts on CodeMode MCP's which was also excellent work that advanced our thinking.
As a side node, we're beginning to see the outline of a self recursion scaffold, with a number of different industries all coming up with the same scaffold including myself for different reasons.
Cloudflares exmaple, my own work, https://arxiv.org/pdf/2607.17044 this Leni paper, another being reviewed - dont have a link yet, all come about to the same conclusion in separate domains - I find this facinating
> The Cloudflare folks apparently want security issues reported via HackerOne (which wouldn’t let me log in because the Cloudflare CAPTCHA HackerOne uses seems to be broken…).
Lots of extra words in this blog post but the direction is right: companies prefer to build their own AI code review solutions than use off the shelf products.
I’m the founder of a W24 company and we pivoted away from AI Code Review for this reason
It’s odd how uninteresting a blog post about an AI system is.
“We defined code review rules as if they were linter rules and let the AI agent review code”
I don’t really need to know a lot more than that. I can already clearly imagine how it’s achieved. I don’t need a nine minute read.
I've been working a lot on building a system like this personally over the last few months - Cloudflare are either not stating or missing one important issue. While they are doing loop improvement on the Standards themselves, they are forgetting to do improvement on the model. So in their language, they are improving the Codex, but they are NOT improving the reviewer and they need to close that loop.
Great bit of work, I rate it up there with their thoughts on CodeMode MCP's which was also excellent work that advanced our thinking.
As a side node, we're beginning to see the outline of a self recursion scaffold, with a number of different industries all coming up with the same scaffold including myself for different reasons.
Cloudflares exmaple, my own work, https://arxiv.org/pdf/2607.17044 this Leni paper, another being reviewed - dont have a link yet, all come about to the same conclusion in separate domains - I find this facinating
Meanwhile: https://textslashplain.com/2026/08/04/security-is-hard-yall/
> The Cloudflare folks apparently want security issues reported via HackerOne (which wouldn’t let me log in because the Cloudflare CAPTCHA HackerOne uses seems to be broken…).
Lots of extra words in this blog post but the direction is right: companies prefer to build their own AI code review solutions than use off the shelf products.
I’m the founder of a W24 company and we pivoted away from AI Code Review for this reason
Oof. All coding standards have to be written as an RFC document?
From an SRE's perspective, this is a good thing.
[dead]
Oh hey, more AI slop from Cloudflare.
Too bad everything they touch turns to poop