AI Code Review Prompt for Laravel PRs
Pasting a diff into ChatGPT and asking "can you review this?" gets you "this looks good overall, consider adding more comments" about 80% of the time, even when the diff has a real mass-assignment hole or an N+1 query sitting in a loop. The problem isn't the model. It's the prompt. An AI code review prompt for Laravel pull requests needs to actually tell the model what Laravel-specific failure modes look like, or it defaults to generic software-review advice that could apply to any language.
I started doing this on a client project earlier this year after I caught myself rubber-stamping AI reviews that missed the exact kind of bug I'd have caught in five seconds doing it manually. The fix wasn't a smarter model — it was a much more specific prompt.
Why the generic prompt fails on Laravel code specifically
Laravel hides a lot of its real behavior behind magic: Eloquent relationships that silently fire a query per row, mass assignment that works fine until someone passes an unexpected field, middleware stacks that make it non-obvious whether a route is actually protected. A generic "review this code" prompt has no reason to go looking for any of that. It reviews what's visible on the screen — variable names, obvious logic errors, missing null checks — and Laravel's actual landmines are almost never visible on the screen. They're one layer down, in how the framework resolves things at runtime.
So the model isn't wrong when it says the diff looks fine. It's answering a different, much shallower question than the one you actually need answered.
The naive prompt everyone pastes in
This is roughly what most people — including me, for a while — paste into an AI chat window along with a diff:
Please review this Laravel pull request for bugs, code quality issues,
and best practices. Let me know if anything looks wrong.
[paste diff here]
It's not a bad instinct, it's just too thin. There's no mention of what kind of bugs matter in this specific codebase, no mention of the framework conventions being used, and nothing telling the model to actually trace data flow instead of pattern-matching on style. You get back comments about naming and docblocks because that's the laziest thing to say about any diff, in any language.
A prompt that actually catches Laravel-specific issues
Here's the version I actually use now. It's longer, and that's the point — it gives the model a checklist of the exact failure modes Laravel code produces, instead of leaving it to guess:
You are reviewing a Laravel pull request. Go through the diff and check
specifically for:
1. Mass assignment: any model missing $fillable/$guarded that now accepts
new request input, or any ->create()/->update() call fed directly from
$request->all().
2. N+1 queries: any loop over a relationship that isn't eager-loaded
with() or withCount(), especially inside a controller or a Blade view.
3. Authorization: any new or changed route/controller action that touches
another user's data without a policy check, gate, or middleware guard.
4. Queued jobs: any job that isn't idempotent but could plausibly be
retried (check for ShouldQueue + no uniqueness guard).
5. Validation: any request class or inline validate() call that's missing
rules for a field that's actually used downstream.
For each issue found, quote the exact line, explain the failure scenario
in one sentence, and suggest the specific fix. If none apply, say so
explicitly rather than giving generic praise.
[paste diff here]
That last line matters more than it looks — "say so explicitly rather than giving generic praise" is there because models default to being agreeable, and a review tool that can say "I found nothing" convincingly is more useful than one that always finds something to mention.
What this actually catches, in practice
On one PR, the naive prompt said the code "looked clean and followed good practices." The structured version flagged that a new OrderController@update method called $order->update($request->all()) with no $fillable guard on the Order model — meaning a client could pass user_id in the request body and reassign an order to a different account. That's not a style nit, that's a real authorization bypass, and it was sitting in a 40-line diff that would've sailed through a quick human skim too.
I've stopped trusting any AI review tool, including the ones baked into GitHub, that doesn't let me see or edit the underlying prompt. If I can't tell it what to look for, I have no real idea what it's actually checking, and "looks good to me" from a model is worth exactly as little as "LGTM" from a teammate who skimmed it on their phone.
Where this falls short
This prompt still won't catch everything — it won't know your team's specific conventions unless you add them, and it can't actually run the code, so it'll miss anything that only shows up at runtime with real data (a race condition in a job, a timezone bug that only triggers near midnight). Treat it as a first pass that catches the categories of bug that are easy to describe and easy to miss, not a replacement for actually running the test suite.
The checklist above is specific to Laravel, but the pattern generalizes: don't ask an AI reviewer to "review the code," tell it what your framework's actual failure modes are and make it prove a negative when it doesn't find any. That one change is the difference between a review that rubber-stamps everything and one that would've caught the bug I described above before it shipped.
Related posts
AI Code Review Prompts for Pull Requests
Copy five practical AI code review prompts for pull requests, plus a Node.js script to run them in CI. Catch bugs and security issues faster.
AI Prompts for Better Git Commit Messages
Most AI commit message tools just summarize the diff. Here's the AI prompt and git hook I use that actually captures the real reason behind a change.
AI Prompt to Write Unit Tests for Legacy PHP
Learn how to write an AI prompt that generates real unit tests for legacy PHP code, including the hidden edge cases a generic prompt misses.
AI Prompts to Debug Node.js Stack Traces
Debugging Node.js stack traces with AI works only with the right prompt structure. A real TypeError, a proven prompt, and the fix, step by step.
0 Comments
No comments yet — be the first to share your thoughts.