AI built it. Can you find what’s wrong?

Short code-review challenges focused on the issues that matter in production.

Beginner · Security

Challenge 001

Find 7 production problems in this AI-generated FastAPI endpoint.

API_KEY = "sk-live-secret"
@app.get("/users")
def users(q: str):
    sql = f"SELECT * FROM users WHERE name = '{q}'"
    print("query", sql)
    return db.execute(sql)
Issues

Hardcoded secret; missing authentication; SQL injection; no input constraints; sensitive logging; no error handling; no result limiting.

Intermediate · Reliability

Challenge 002

Find the failure modes in this external API call.

def get_data(url):
    return requests.get(url).json()
Issues

No timeout; no status handling; no retry strategy; no schema validation; no exception handling.

Intermediate · AI Agents

Challenge 003

Find risky agent-tool behavior.

tools = [shell, email, delete_file, database]
agent.run(user_prompt)
Issues

Broad tools; no least privilege; no approval gates; no sandbox; no audit log; prompt can directly trigger destructive actions.

Advanced · RAG

Challenge 004

Find the weaknesses in this RAG pipeline.

docs = load_all_files()
chunks = [d.text for d in docs]
index.add(embed(chunks))
return llm(question + retrieve(question))
Issues

No chunking strategy; no metadata; no access control; no source citations; no evaluation; possible prompt injection; no update strategy.

Beginner · Observability

Challenge 005

Find what is missing from these logs.

print("started")
print("done")
Issues

No structured fields; no request ID; no latency; no error context; no severity; no environment/service metadata.