# you own the code you never read

Canonical: https://brew.new/templates/vueschool/you-own-the-code-you-never-read

Brand: vueschool.io
Category: newsletter

![Preview of you own the code you never read](https://cdn.brew.new/email-preview-bece2e6db52de000-tracking_r57rernd0t5q1q0733dedhamf58dt88s-1789071895379.png)

## Email content

Hi there,

Your agent's code is probably right. That was never the hard part.

The hard part is everything it decided to get there. The moment that code ships, those decisions are yours to own and maintain, whether you watched them happen or not.

It shows up most in a single function that reads like one job but actually does four.

Take createComment. It saves the comment. But inside an observer you'd never open, it also:

subscribes you to the thread

loads every subscriber

emails all of them

Nothing in the name or the call site says so. The tests pass, because the comment did get created.

It works, and all four are yours now, the ones you saw and the ones you didn't.

None of that is a mistake. The model is being helpful. It hangs the extra work on an event, the way the framework wants, a hop away from the line you're reading.

So the effects land where a review skims past, like observers, event listeners, middleware, and helper functions. A careful reviewer reads the obvious file top to bottom, finds nothing worth flagging, and signs off, because the real work was never where they were looking.

Reviewing AI-written code

So stop reading line by line, and sweep for it instead.

Point your agent at the diff and ask it straight:

Find every function, observer, event listener, middleware, and helper that writes to the database, sends anything over the network, or changes shared state. Then tell me which ones do more than their name says.

That gives you the list. Then work through it, in order:

Decide which ones belong. The sweep surfaces every effect, and plenty of them should be there. Telling the difference is the actual skill.

Move each real one into a named action. Have the agent propose the refactor before it touches anything. Now createComment creates a comment and nothing else, and the notification is a call the next reader can actually see.

Run the sweep once more. Confirm the effects are out in the open now, and you didn't just move the pile to a quieter spot.

Then teach the agent to keep them in the open.

Almost nobody does this. Write one rule into the file your agent reads on every run, the AGENTS.md or your tool's equivalent:

Keep side effects (database writes, network calls, shared-state changes) out of observers, event listeners, middleware, and helpers. Put them in a named action the caller triggers on purpose.

A review you run once is a chore. A review that teaches your agent is a system, and the next hundred functions come out clean.

But deciding what belongs in the function and what's just along for the ride is the part no tool hands you. A linter only sees the code in front of it, and a test only checks the behavior you thought to assert. Neither one knows what createComment should and shouldn't do. That call is yours, and it doesn't get easier as the models get better.

This is one move from our full workflow on reviewing AI-written code. It also covers the four-pass review order, the five security checks for AI code, and the tests that pass while testing nothing. We ship new workflows and lessons every week, because the tools keep moving. Staying sharp at owning what ships is how you keep pace.

A lot of it is already free. A dozen of our skills are open source, no account required, and drop straight into your agent. One of them, the Triage Skill, sorts a big diff by risk in 60 seconds. Grab them at github.com/unlearndev/skills.

The price is in the diff.

One last thing. The more Unlearn ships, the more it costs to join. A lot is shipping right now, so the price goes up next week, from $219 to $299. Lock in before then and you keep $219 for as long as you stay. We'd rather you hear it from us now than find it gone later.

Lock in $219/yr →

The Unlearn.dev Team

P.S. Try the sweep on your next PR, before you read it line by line. Two minutes is all it takes to see what's been riding along.

--

This email is authored by Unlearn.dev,

part of the same family as

vueschool.io.

You're getting it because you're on the

vueschool.io list, and we thought it was useful to you.

Not for you?

Unsubscribe from Unlearn.dev emails, and you'll still hear from

vueschool.io as usual.

[Open and remix this design](https://brew.new/templates/vueschool/you-own-the-code-you-never-read)

[Browse email designs](https://brew.new/browse/templates)
