4.c: Advanced Scenarios
These scenarios showcase the ability of AI coding agents to handle more comprehensive or specialised development tasks, often involving multiple files, broader codebase understanding, or specific domain knowledge.
Project Scaffolding
AI coding agents can help set up the basic structure for new projects, creating directories and initial files.
Walkthrough (Claude Code or Codex CLI):
- Setup: Create an empty repository on GitHub (e.g.,
my-flask-app) and open it in your terminal agent. - Prompt:
Set up a basic Python project for a Flask web application in the current repository (`my-flask-app`). Create the following structure and files: - A `requirements.txt` file listing `Flask` and `python-dotenv`. - An `app/` directory. - Inside `app/`, create `__init__.py` to make it a package and initialize a basic Flask app instance. - Inside `app/`, create `routes.py` with a simple "Hello World" route at `/`. - A `run.py` file in the root to import and run the Flask app from the `app` package. - A `.flaskenv` file with `FLASK_APP=run.py` and `FLASK_ENV=development`. - A `static/` folder (empty). - A `templates/` folder (empty). - A basic `README.md` with instructions on how to set up a virtual environment, install dependencies from `requirements.txt`, and run the app using `flask run`. - Agent Action: The agent will attempt to create these files and directories within the repository. It will populate
requirements.txt,__init__.py,routes.py,run.py,.flaskenv, andREADME.mdwith appropriate content. - Review: Carefully review all generated files and the directory structure. Test the setup instructions in the
README.md.
Pull Request Review
AI coding agents can be asked to review code changes submitted as a diff or a pull request URL, providing feedback on quality, potential bugs, and best practices.
Walkthrough (Claude Code or Codex CLI):
- Scenario: You have a pull request on GitHub with some Python code changes. You want an AI review.
- Get PR Diff URL: Go to the pull request on GitHub, and on the "Files changed" tab, you can often find a way to view the raw diff or get a URL ending in
.diff. For example:https://github.com/your-org/your-repo/pull/123.diff - Prompt the agent:
Please review the changes in this pull request: https://github.com/your-org/your-repo/pull/123.diff Focus on: - Python best practices and idiomatic code. - Potential bugs or logical errors. - Readability and maintainability. - Missing error handling or edge case considerations. - Adherence to PEP 8. Provide your feedback as a list of comments, referencing file names and line numbers where possible. - Agent Action: The agent will load the patch (diff), analyse the changes, and provide textual feedback based on your criteria.
Note: Direct PR URL review might require specific integrations or permissions. Using the
.diffURL is a more general approach. Claude Code with a GitHub MCP server can access PRs directly.
Security Audits (Conceptual)
AI coding agents can be tasked with identifying potential security vulnerabilities in a codebase. This is an advanced use case and should always be complemented by human expertise and dedicated security scanning tools.
Walkthrough (CLI - Conceptual):
- Navigate: Navigate to the root of a small sample codebase (e.g., a simple Node.js/Express web application).
- Prompt (using a hypothetical recipe or detailed instruction):
codex "Analyze the Express.js application in the current directory for common web security vulnerabilities. Specifically look for: - Potential XSS (Cross-Site Scripting) vulnerabilities in how user input is handled in routes and templates. - Risks of SQL Injection if database interactions are present (check for parameterized queries). - Insecure direct object references (IDOR). - Misconfigured security headers. - Use of outdated or vulnerable dependencies (check `package.json`). Generate a report in Markdown format detailing potential findings, their locations (file and line), severity (High/Medium/Low), and suggested remediations." --model gpt-4.1 - Agent Action: The agent will attempt to analyse the code based on the patterns described. Its output would be a textual report. Important: This is a conceptual example. Real-world security auditing is complex. AI agents can assist by finding patterns, but they are not a replacement for thorough security reviews by professionals or specialised SAST/DAST tools.
Code Transpilation
AI coding agents can translate code from one programming language to another, though the quality and completeness can vary depending on language complexity and feature parity.
Walkthrough (Claude Code or Codex CLI):
- Provide Python Snippet:
def get_user_greeting(username, is_premium_member=False): greeting = f"Hello, {username}!" if is_premium_member: greeting += " Welcome to our premium services!" return greeting - Prompt:
Rewrite the following Python code in idiomatic JavaScript (ES6). Ensure default parameter values and string interpolation are handled correctly. Python code: ```python def get_user_greeting(username, is_premium_member=False): greeting = f"Hello, {username}!" if is_premium_member: greeting += " Welcome to our premium services!" return greeting - Agent Output (Example):
const getUserGreeting = (username, isPremiumMember = false) => { let greeting = `Hello, ${username}!`; if (isPremiumMember) { greeting += " Welcome to our premium services!"; } return greeting; };
Generating SQL Migrations
Terminal-based agents, with their understanding of repository context, can often infer the Object-Relational Mapper (ORM) being used (e.g., SQLAlchemy, Django ORM, Sequelize) and help generate database migration files.
Walkthrough (CLI - Conceptual with Django):
- Scenario: In a Django project, you've added a new field
last_login_ip(CharField) to yourCustomUsermodel inusers/models.py. - Prompt (CLI):
codex "I've added a `last_login_ip` CharField (max_length=45, null=True, blank=True) to the `CustomUser` model in the `users` app of my Django project. Generate the necessary Django migration files for this change. Name the migration `add_last_login_ip_to_customuser`." - Agent Action (Ideal):
- The agent recognises it is a Django project.
- It might run
python manage.py makemigrations users --name add_last_login_ip_to_customuserin its sandboxed environment or directly generate the content of a new migration file (e.g.,users/migrations/000X_add_last_login_ip_to_customuser.py). - The generated file would contain Python code defining the
AddFieldoperation. Note: Direct execution ofmakemigrationsdepends on the agent's environment setup. Claude Code with access to a Python virtualenv can run this directly; otherwise, the agent generates the migration file content based on its understanding of Django's migration structure.
These advanced scenarios push the boundaries of what AI can assist with in development, moving towards more autonomous and deeply integrated partnership. However, they also require more careful prompting, context provision, and rigorous review of the outputs.