Findings become fixes.

Qodo flags a real issue on a pull request. A TrueForge agent reproduces it in a sandbox, writes the fix and a test, then stops and waits for a human before anything ships.

PR #2 · approved & open
folder fix-radar-demo-target
priority_high severity: medium
smart_toy TrueForge agent
rate_review reviewed by Qodo
Agent run

Execution trace

PR #1 → PR #2
  1. flag

    Qodo flags app.py lines 66–69

    Triggered by commenting /agentic_review. Finding: “Total loads every expense” — the endpoint pulls every row into Python and sums there instead of letting SQLite aggregate.

  2. travel_explore

    Agent investigates via GitHub MCP

    pull_request_read, get_file_contents, list_commits — confirms the defect itself instead of trusting the one-line description.

  3. deployed_code

    Reproduces and fixes in a Daytona sandbox

    Clones the repo, installs dependencies, runs the existing tests, rewrites the endpoint to use SELECT COALESCE(SUM(amount), 0), adds a regression test. pytest -k total passes.

  4. visibility

    Reports scope honestly

    Spots an unrelated, pre-existing ZeroDivisionError nearby — and leaves it untouched, since it wasn't what Qodo flagged.

  5. error

    Hits a real permission wall

    First push fails: 403 Resource not accessible by personal access token. Reports the exact error and stops — doesn't invent a workaround.

  6. how_to_reg

    Human approves — agent opens the PR

    Token scope corrected, human says yes. Agent opens PR #2 with the fix, the test, and a description linking back to the finding.

description app.py
+8·PR #2
@@ -60,3 +66,9 @@ def average_endpoint():
return jsonify({"average": average_amount(amounts)})
+@app.route("/expenses/total")
+def total_endpoint():
+ conn = get_db()
+ row = conn.execute("SELECT COALESCE(SUM(amount), 0) AS total FROM expenses").fetchone()
+ conn.close()
+ return jsonify({"total": row["total"]})
Stack & evidence

Built with

TrueForge Qodo GitHub MCP Daytona sandbox Flask + pytest

Evidence

Telemetry

Run log

Qodo: finding posted on PR #1
agent: read PR + file via GitHub MCP
sandbox: daytona instance up, deps installed
agent: fix + regression test written
pytest: -k total — passed
github: 403, push rejected
human: token fixed, approved
agent: opened PR #2