Review
Aug 2026
PRWeaver: Evaluating LLM-Based Code Auditors against Long-Horizon Malicious Pull Requests
The results show that access to repository history is insufficient: concealment becomes most effective when benign and malicious changes jointly occupy the auditor's active review context or when the stated purpose plausibly accounts for the attack-bearing diff.
Yuekun Wang, Mingfei Cheng, Xiaofei Xie
· 0 citations