First, I understand what the code is actually doing.
Then I test the happy path and the paths the AI may not have considered.
I check the stack trace, inspect the data flow, test edge cases, review dependencies and security-sensitive areas, and verify that the fix doesn't introduce another problem.
This is becoming even more important as coding agents take on larger development tasks. GitHub's current tooling, for example, combines code review, testing, dependency checks, secret scanning, and security analysis around agent-generated changes.
Three checks I put beside a post-purchase email draft:
Does the main CTA open the exact page the copy promises?
Does the recommendation match the product the customer bought?
What stops a refill message after another order or when a subscription already covers the item?
These questions shaped my new matcha-shop demonstration: three email drafts, an evidence-linked review and a 12-case QA plan. The handoff makes the remaining decisions explicit, including delivery evidence and refill timing.
This is self-directed, AI-assisted work for a hypothetical shop. Every native account test is marked NOT RUN, and no client or revenue results are claimed.