ForgeLayer

GitHub-native review artifact

PR Comment Preview

ForgeLayer turns review-run output into a clean, GitHub-ready comment preview while keeping posting disabled by default.

Preview only. No GitHub API calls, no auto-merge, no live agent execution, and no production persistence are used by this demo page.

Enterprise summary

ForgeLayer Review

ForgeLayer reviewed acme-ai-checkout/acme-checkout-web#42. Risk is HIGH; merge recommendation is needs human review.

Safety summary

Human-controlled by default

GitHub posting is disabled by default. Preview only unless GitHub posting is explicitly enabled. ForgeLayer does not call GitHub APIs from this preview surface. ForgeLayer does not execute agents, merge code, or grant repo access. Generic Platform Guidance: Human approval remains required before production merge.

  • GitHub posting is disabled by default.
  • Preview only unless GitHub posting is explicitly enabled.
  • ForgeLayer does not call GitHub APIs from this preview surface.
  • ForgeLayer does not execute agents, merge code, or grant repo access.
  • Generic Platform Guidance: Human approval remains required before production merge.

Action items

Before this is used on a PR

  • Keep this as a preview while GitHub posting is disabled by default.
  • Review the copy-ready markdown before using it in GitHub.
  • Complete required human checks before merge.
  • Confirm tests, evidence, and policy follow-ups are satisfied.
  • Treat safe_to_post as false until the blocked reason is resolved.
  • Resolve warning: GitHub posting is disabled.

Comment anatomy

Enterprise PR comment sections

headline

Headline

ForgeLayer Review

status

Status

GitHub posting is disabled by default. This is a copy-ready preview only.

risk summary

Risk Summary

HIGH

merge recommendation

Merge Recommendation

needs human review

required human checks

Required Human Checks

* security * prompt * code-owner

evidence needed

Evidence Needed

* Prompt injection risk * Payment webhook touched * Auth/session touched

changed files context

Changed Files / Context

Refund assistant and checkout webhook changes touch payment, prompt, and auth/session surfaces. Security and prompt review are required before merge.

next steps

Next Steps

* Resolve blocking findings. * Regenerate the ForgeLayer review before merge.

safety note

Safety Note

GitHub posting is disabled by default. Preview only unless GitHub posting is explicitly enabled. ForgeLayer does not call GitHub APIs from this preview surface. ForgeLayer does not execute agents, merge code, or grant repo access. Generic Platform Guidance: Human approval remains required before production merge.

Copy-ready preview

GitHub Markdown

## ForgeLayer Review

### Summary

ForgeLayer reviewed acme-ai-checkout/acme-checkout-web#42. Risk is HIGH; merge recommendation is needs human review.

### Review Status

* Status: needs manual review
* Generated: 2026-07-09T09:00:00.000Z

### GitHub Check Preview

* Title: ForgeLayer preview: merge blocked
* Status: completed
* Conclusion: failure
* Preview only: true
* Would block merge: yes
* Required human review: yes

### Risk / Merge Recommendation

* Risk: HIGH
* Merge recommendation: needs human review

### Key Findings

* Prompt injection risk
* Payment webhook touched
* Auth/session touched

### Required Human Checks

* security
* prompt
* code-owner

### AI Work Record

Work type: feature_build. Scope: sensitive_paths_touched.

### RepoBrain

Refund assistant and checkout webhook changes touch payment, prompt, and auth/session surfaces. Security and prompt review are required before merge.

### Next Steps

* Resolve blocking findings.
* Regenerate the ForgeLayer review before merge.

### Safety note

Preview only unless GitHub posting is explicitly enabled. ForgeLayer does not execute agents, merge code, or grant repo access.
Posting enabled: no. Safe to post: no.