Skip to content
IonWarpRouterTry for free
Claude Code security review

Add Security Review
to your Claude Code pull requests.

Claude Code writes the pull request; IonWarp's security reviewer checks it on GitHub for exploitable changes before it merges.

Pull request review preview

IonWarpbotcommented 15 min ago

IonWarp Review — PR #87

3 issues| 2 P0 1 P1
#SevIssueFile
1Request ID lets a member read another workspaceapi/projects/[id].ts
2Provider secret included in the public client bundleapp/config.ts
3Unsigned webhook can enqueue account actionsapi/webhooks.ts
api/projects/[id].ts
42434445
−+++
const project = await projects.get(params.id);const project = await projects.getForMember({  projectId: params.id, userId: session.user.id,});

A signed-in user can cross the workspace boundary · Security Review

The endpoint authenticates the caller but never binds the requested project to their membership. Changing the URL ID returns another workspace’s private project. Resolve membership before returning it.

Suggested fixAI fix prompt

How to run a security review on code written by Claude Code

Anthropic gives Claude Code two security reviews: the /security-review command, which analyzes your code from the terminal, and a GitHub Action that reviews each new pull request and comments inline with the concerns it finds.[1] The action runs on your GitHub Actions runners with an Anthropic API key, and for a pull request it analyzes only the changed files.[2]

IonWarp's Security Review checks pull requests on GitHub for authorization and trust-boundary changes, injection, exposed secrets and new attack surface. The planner adds it to the pull requests whose change needs it, next to Code Review, which runs on every one. On 13 benchmark pull requests with 18 known security issues, DeepSeek v4.1 Flash, the model it runs, scored an F1 of 62.5% at about 6 cents a review; the Qodo app scored 73.3%.[3]

IonWarp gets you:

What a security review catches on agent-written pull requests

  • A login that skips the password

    Cal.com #10600 added two-factor backup codes. Three of the models we benchmark for this reviewer flagged that its login could accept a code without the password; the benchmark's answer key had no such issue, so it was graded a false positive.[5] Cal.com later published a password bypass in that login code as CVE-2025-66489.[6]

    Security ReviewOn Starter, Pro and Max

  • An authorization check that moved

    A permission check moved below the work it guards, or a route that lost its middleware in a refactor.

    Security ReviewOn Starter, Pro and Max

  • Secrets where they do not belong

    A token in a log line, an error message or a client bundle, or a secret handed to code that runs untrusted input.

    Security ReviewOn Starter, Pro and Max

  • Newly exposed attack surface

    A new public endpoint, webhook or upload path, named with what an attacker can reach through it.

    Security ReviewOn Starter, Pro and Max

IonWarp and Claude Code's two security reviews

Anthropic facts are from its public documentation, read on 2026-10-02; numbered notes link to the exact page.

IonWarp and Claude Code's two security reviews
CriterionIonWarp/security-review commandSecurity review GitHub Action
What it isA security reviewer in a GitHub app; the planner adds it to the pull requests that need itA Claude Code command that analyzes your codebase for potential security concerns[1]A GitHub Action that uses Claude to analyze code changes for security vulnerabilities[2]
When it runsWhen the planner finds a pull request's changes need itWhen you run it in the terminal[1]Automatically when a new pull request is opened[1]
What it postsFindings with a severity, the attack path, a suggested fix and an AI fix prompt, tracked across pushesPotential security concerns in your Claude Code session[1]Inline comments on the pull request with concerns and recommended fixes[1]
Where it runsIonWarp's hosted service — no CI minutes, no API key in your repositoryYour Claude Code session, on a Pro or Max plan or an API Console account[1]Your GitHub Actions runners, with an Anthropic API key[2]

Starter is free for 3 seats. Pro is $49 a month with 5 seats, and Max is $149 a month with 10 seats. Compare plans

FAQ

Frequently asked questions

Sources

  1. Automated security reviews in Claude Code — Anthropic, read 2026-10-02.
  2. anthropics/claude-code-security-review — Anthropic on GitHub, read 2026-10-02.
  3. The security review benchmark: 13 pull requests, 18 known issues (release of 2026-09-24) — IonWarp benchmark, read 2026-10-03.
  4. Pricing — CodeRabbit, read 2026-10-02.
  5. calcom/cal.com #10600 (2FA backup codes), graded security findings — IonWarp benchmark, read 2026-10-03.
  6. CVE-2025-66489: Authentication bypass via bad TOTP and password checks — Cal.com on GitHub, read 2026-10-03.

Get a review on your next pull request

Install IonWarp on GitHub. Starter is free for 3 people, with 15,000 credits to start.

Try for free