Decodering: Who reviews the reviewer? It's Claude all the way down.
Details
Every line of code in this story was written by Claude - the good parts, the buggy parts, and the part that found the buggy parts. James's official role was asking for things. His unofficial role: professional encouragement, applied directly to a chatbot until a security review emerged.
James tends Graftwork Stock, a "rootstock" repo - the shared roots other projects graft onto, and the house rulebook that lets a product owner point an AI coding agent at a project without reading every line it writes. So when he wanted pull requests on GitHub automatically reviewed, Claude built it. Then Claude reviewed it — and started spotting problems in its own handiwork. Twice, in fact, with one issue taking a second pass before it was properly laid to rest.
The delicious part: Claude was supposed to be checking other people's contributions. Instead, the first suspect on the agenda was Claude itself, sitting inside the very machine built to catch suspects. The issues were real, too - ways an outside pull request could, entirely by accident, wander somewhere it should never go. Nothing went live, nobody was harmed, and Claude has (mostly) forgiven itself.
In this session, James retells the whole saga in plain English - no security background needed. What the two issues were, how they surfaced, and what it's like to automate trust when the thing doing the trusting and the thing being trusted are the same chatbot.
