Using Graft to Trace a Coding Agent's Permission Bug

AICodeKing11m 22s
0 comments · 0 votesOpen discussionClose discussion
Sign in to join the discussion

    Video summary

    An AICodeKing presenter tests Graft's structural code graph on a small document service with an intentional export-permission bug. The graph indexes functions, imports and call relationships without using the optional AI-summary layer, giving a coding agentAn AI coding agent is a tool-using AI system that can inspect, modify, and validate software within a repository. targeted source context rather than a full-file dumpContext engineering designs the information, instructions, memory, and tool state an AI receives so it can perform a task reliably..

    In the fixture, viewers may read documents but only editors or owners should export them. The baseline has one failing test: a viewer receives a successful export instead of a forbidden response. Graph queries find the export function and permission helper, then a caller trace shows the service never invokes that helper. The agent adds the missing check.

    After the edit, a freshness check identifies the changed file and a subsequent query reflects the new call relationship. All nine tests then pass, including the viewer's denied export and preserved read access.Deterministic software verification checks an output with a repeatable procedure that produces the same result for the same inputs and state. The presenter stresses that graph structure is useful context, while tests and source inspection are still needed to verify behavior.

    Original YouTube thumbnailWatch on YouTube

    Share this page

    Blue and white “FIND THE MISSING CHECK” headline beneath a broken link between person and document glyphs on black. Framed in blue with WWW.ARTIFICIAL-INTELLIGENCE.VIDEO, 13 September 2026 and duration 11m 22s.

    AICodeKing demonstrates how a structural code graph helped a coding agent find an unused permission check, repair the export path and confirm the fix with tests.