Skip to content

test: add sample code for pr-agent review - #1

Closed
Prateekbala wants to merge 1 commit into
mainfrom
test/pr-agent-review
Closed

Prateekbala wants to merge 1 commit into
mainfrom
test/pr-agent-review

Conversation

@Prateekbala

Copy link
Copy Markdown
Owner

No description provided.

Comment thread test-review-me.ts
Comment on lines +11 to +12
function getUser(db: any, userId: string) {
return db.query("SELECT * FROM users WHERE id = " + userId);

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟠 Security · high — SQL injection via string concatenation

The getUser function builds a SQL query by concatenating userId directly, allowing an attacker to inject arbitrary SQL. This can lead to data leakage or modification.

Suggested change
function getUser(db: any, userId: string) {
return db.query("SELECT * FROM users WHERE id = " + userId);
function getUser(db: any, userId: string) {
return db.query('SELECT * FROM users WHERE id = ?', [userId]); // Use parameterized query
}

Confidence 96%

Comment thread test-review-me.ts
}

// Hardcoded secret
const API_KEY = "sk-prod-abc123supersecretkey";

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟠 Security · high — Hardcoded secret API key

A secret API key is committed in source code, exposing credentials that could be abused to access the production service. This constitutes a credential leakage risk.

Suggested change
const API_KEY = "sk-prod-abc123supersecretkey";
const API_KEY = process.env.API_KEY; // Load from environment variable

Confidence 95%

Comment thread test-review-me.ts
Comment on lines +2 to +4
async function fetchUser(id: string) {
const result = fetch(`https://api.example.com/users/${id}`);
return result;

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Bug · medium — Missing await on async fetch call

The function fetchUser is declared async but calls fetch without awaiting, so it returns a Promise instead of the resolved response. Callers expecting a resolved value may get an unexpected Promise, leading to runtime errors.

Suggested change
async function fetchUser(id: string) {
const result = fetch(`https://api.example.com/users/${id}`);
return result;
async function fetchUser(id: string) {
const result = await fetch(`https://api.example.com/users/${id}`);
return result;
}

Confidence 90%

Comment thread test-review-me.ts
Comment on lines +15 to +19
// Empty catch
async function riskyOp() {
try {
await fetchUser("123");
} catch (e) {}

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Bug · low — Empty catch block swallows errors

The catch block catches exceptions from riskyOp but does nothing, silently ignoring failures. This makes debugging difficult and can hide runtime errors.

Suggested change
// Empty catch
async function riskyOp() {
try {
await fetchUser("123");
} catch (e) {}
} catch (e) {
console.error('riskyOp failed:', e);
throw e; // Re‑throw or handle appropriately
}

Confidence 85%

@Prateekbala

Copy link
Copy Markdown
Owner Author

Review

This PR adds a sample test file that contains multiple security and quality issues. The code builds a raw SQL query using string concatenation, includes a hard‑coded API key, calls fetch without awaiting, and swallows errors in a catch block. These defects expose the system to injection attacks, credential leakage, runtime failures and debugging difficulties.

Risk: 🟠 high
Findings: 4 inline comments

Highlights

  • SQL injection via string concatenation
  • Hardcoded secret API key
  • Missing await on async fetch call
  • Empty catch block swallows errors
Files reviewed

Test review code — Verify that the SQL query uses parameterized statements, remove the embedded API key or externalize it, add await to the fetch call, and handle errors in the catch block.

  • test-review-me.ts

Run cost: 6825 tokens

@Prateekbala Prateekbala closed this Oct 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant