ScreenshotNeo

BlogEngineering

Artificial Intelligence in Software Engineering: Use Cases and Tools

Learn where AI fits in software engineering, how to evaluate developer tools, and how to keep generated changes reviewable, tested, and secure.

By the ScreenshotNeo team4 October 202610 min read

Artificial intelligence is used in software engineering to help investigate codebases, plan changes, draft and edit code, write tests and documentation, review pull requests, find vulnerabilities, and assist with maintenance and operations. These capabilities can shorten individual steps, but an AI suggestion is not evidence that a change is correct, secure, or maintainable. Choose tools around your team’s workflow and controls, then validate every consequential change with review and tests.

This guide explains the main use cases, compares documented tool workflows, and gives a practical adoption and review process for developers and engineering teams.

1. What AI does in software engineering

AI tools range from inline code completion to agents that inspect a repository, propose a plan, edit multiple files, and prepare a change for review. Some tools also assist with tests, documentation, security scanning, upgrades, and cloud operations. The supported tasks and controls vary by product, plan, client, and organization policy.

Engineering activity Useful AI assistance What the engineer still owns
Requirements and planning Summarize a task, ask questions about a codebase, identify likely files, propose an implementation plan. Confirm product intent, constraints, architecture, and acceptance criteria.
Implementation Suggest code, draft a function, edit files, or implement a scoped issue. Check behavior, edge cases, dependencies, conventions, and the complete diff.
Testing and review Draft test cases, explain a diff, identify possible defects, and suggest review comments. Choose meaningful tests, reproduce failures, judge tradeoffs, and approve or reject changes.
Documentation and maintenance Draft docs, explain unfamiliar code, refactor, or assist with upgrades. Confirm compatibility, migration behavior, accuracy, and operational impact.
Security and operations Surface potential vulnerabilities, suggest remediations, and answer questions about cloud resources. Perform threat-aware review and verify fixes; a product scan is not a complete security assessment.

2. Common use cases and practical examples

Repository discovery and planning

Use an assistant to orient yourself in an unfamiliar service or prepare a change plan. Give it the task, relevant constraints, and a request to cite file paths or symbols it relied on. Check those references in the current checkout: summaries can miss recent changes, runtime behavior, or undocumented architecture decisions.

Task: Add pagination to GET /widgets.
Before editing:
1. Find the route, data access layer, API conventions, and existing tests.
2. Summarize the current behavior and propose a minimal plan.
3. List assumptions and questions that could change the design.
Do not edit files until I approve the plan.

Implementation and editing

For a coding task, define observable behavior, constraints, and what not to change. Keep work bounded enough to review. Ask for a diff summary and tests run; independently inspect both. For broad or multi-file changes, split the work into reviewable steps instead of asking for a large rewrite in one prompt.

Implement the approved pagination plan.
Requirements:
- Preserve the existing response shape except for the documented pagination fields.
- Reject negative page sizes and cap the maximum at the service limit.
- Add tests for empty results, the first page, the final partial page, and invalid input.
- Do not change database schema or unrelated endpoints.
At the end, summarize changed files, assumptions, and verification still needed.

Testing and code review

AI can suggest tests or review comments, but it cannot establish that the test suite covers the important failure modes. Check that tests fail when the feature is broken, cover boundaries and errors, and run in the same environment used by CI. Treat review output as leads to investigate, not as a pass/fail certificate.

Documentation, refactoring, upgrades

These tasks often affect multiple files or depend on version-specific behavior. Ask for a bounded diff, inspect changed APIs and configuration, run relevant tests, and verify migration or rollback steps. For documentation, compare claims against the actual implementation and current operational procedure.

Security and cloud operations

Use security suggestions to focus human investigation. Confirm whether a finding is reachable and exploitable in your context, inspect the proposed remediation for regressions, and use your established security checks. The NIST NCCoE DevSecOps project provides lifecycle context aligned with the Secure Software Development Framework; the cited document is a preliminary, rolling draft, not a final standard. NIST NCCoE DevSecOps project.

3. Tools and how to compare them

The following are documented examples, not a ranking. Confirm current feature availability, plan entitlements, and administrative settings before adopting a tool; these details can change.

Tool Documented workflows Evaluation questions
GitHub Copilot Code suggestions, codebase questions, issue-to-task agent workflows, file changes, pull-request review, and organization controls. Does it fit your GitHub and IDE workflow? Which agent permissions and policies are enabled? Which features are available on your plan and client?
Amazon Q Developer Code suggestions and chat, private repository questions, tests, vulnerability scanning, refactoring, documentation, upgrades, AWS architecture guidance, and operational assistance. Does your team benefit from AWS integration? How are repository access and security controls managed? Check current product lifecycle and migration guidance.
OpenAI Codex Positioned as an AI coding partner with individual and team plan options. Compare team administration, current entitlements and usage limits, and fit with your development workflow. Verify current plan details before budgeting.

Compare tools against your actual tasks and operating constraints, not a generic “best coding assistant” list. Useful criteria include:

  • Integration: IDE, repository host, issue tracker, CI, and documentation access.
  • Autonomy: whether it suggests text, edits a workspace, runs commands, or works asynchronously; whether each action requires approval.
  • Context: which repositories and files it can read, how context is selected, and how stale or irrelevant context is handled.
  • Review checkpoints: visibility of diffs, command approval, ability to stop work, and traceability of generated changes.
  • Controls: organization policy, access management, data handling, and settings administrators can enforce.
  • Economics: plan limits and the time spent reviewing, correcting, and operating the tool, not only subscription price.

4. A safe workflow for AI-assisted changes

  1. Set the task boundary. Write acceptance criteria, constraints, and prohibited changes. Remove secrets and unnecessary private data from prompts.
  2. Request investigation first. Ask for relevant files, assumptions, risks, and a plan before permitting broad edits.
  3. Limit permissions. Grant only the repository, tools, and command access needed. Review proposed commands before they run.
  4. Keep changes reviewable. Use a branch, inspect the full diff, and separate unrelated work.
  5. Validate behavior. Run focused tests, relevant full-suite checks, static analysis, and security checks according to the project. Verify failures and edge cases rather than relying on an assistant’s summary.
  6. Review as an accountable maintainer. Check correctness, security, compatibility, maintainability, and product requirements. A human owner remains responsible for merge and release decisions.
  7. Record the outcome. Note tool-assisted changes where team policy requires it, and capture defects or review costs to improve the workflow.

5. Measuring value without assuming a productivity gain

Measure a pilot against a defined baseline. Track task completion time alongside review time, rework, escaped defects, test quality, and developer experience. Compare similar task types and account for changes in scope and team composition. A tool can increase the amount of code produced while also increasing review burden.

DORA’s 2025 report describes AI as an “amplifier” of organizational strengths and dysfunctions, based on qualitative data and survey responses from technology professionals. That is a reason to examine the delivery system around the tool; it is not a universal estimate of productivity improvement. DORA 2025 report.

6. Use AI to capture visual evidence of web changes

Software teams can also use AI in visual QA and documentation workflows: capture a page before and after a change, compare layouts across viewports, or attach a reproducible screenshot to a bug report. A screenshot does not replace DOM-level assertions, accessibility checks, or functional tests. For repeatable captures, automate the browser setup and keep the target URL, viewport, state, and wait condition consistent.

DIY capture with Playwright (Node.js)

This runnable example opens a page, waits for the page to load, and saves a full-page PNG. Install Playwright and its browser once, then run the script:

npm install playwright
npx playwright install chromium
// screenshot.mjs
import { chromium } from 'playwright';

const url = process.argv[2] ?? 'https://example.com';
const browser = await chromium.launch({ headless: true });
try {
  const page = await browser.newPage({ viewport: { width: 1440, height: 900 } });
  await page.goto(url, { waitUntil: 'networkidle', timeout: 60_000 });
  await page.screenshot({ path: 'page.png', fullPage: true });
} finally {
  await browser.close();
}
node screenshot.mjs https://example.com

networkidle is not suitable for every site: analytics, polling, or streaming requests may prevent it from settling. If that happens, wait for a meaningful selector or use a short, explicit delay after navigation. For a single component, use page.locator('.selector').screenshot({ path: 'element.png' }). For visual regression, pin the browser version, viewport, device scale factor, fonts, locale, and test data; disable animations or dynamic regions where appropriate.

Or skip the browser setup

ScreenshotNeo is a website screenshot API and MCP server from Yorker Media. One GET request returns an image or PDF, and its options cover full-page capture, selectors, devices, waits, custom CSS and JavaScript, and more. See the ScreenshotNeo API documentation.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

ScreenshotNeo accepts cookie and consent banners like a visitor and removes more than 60 known consent platforms, newsletter popups, and chat widgets before capture; each step can be turned off. Bot checks, blank pages, timeouts, failed loads, and cache hits cost nothing, and response headers identify the page verdict and billing status. Its MCP server gives AI agents tools for screenshots, page information, and PDF capture. The free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000 screenshots. Learn about ScreenshotNeo or sign up for 1,000 free screenshots a month, no card required.

7. Troubleshooting AI-assisted engineering

Symptom Likely cause What to do
The change solves the wrong problem. The prompt omitted acceptance criteria, domain context, or constraints. Clarify expected behavior and ask for a plan before editing; include examples and non-goals.
The assistant cites files or APIs that do not exist. Context is incomplete, stale, or inferred. Ask for repository paths and symbols, verify them locally, and provide the relevant current files.
Tests pass but a defect remains. The tests mirror the implementation or omit boundary cases. Derive tests from requirements independently; add negative, boundary, and integration cases.
A broad edit introduces unrelated churn. The task scope was too wide or the agent was allowed to modify too much. Revert unrelated files, narrow the task, and ask for a smaller diff in a separate branch.
A suggested security fix breaks compatibility. The recommendation ignored threat model, runtime, or dependency constraints. Check supported versions and exploitability, run compatibility tests, and involve the security owner.
The tool cannot access a repository or feature. Plan, client, organization policy, or granted permissions do not include it. Check current vendor documentation and administrator settings; do not assume all features ship on every plan.
Visual captures differ between runs. Fonts, viewport, dynamic content, timing, browser, or external assets changed. Pin environment and test data, wait for a stable selector, and mask genuinely dynamic regions.

8. Performance, reliability, and cost

AI changes latency and cost in several places: model or subscription usage, agent runtime, command execution, CI, and the human time needed to inspect output. Track these separately in a pilot. Prefer scoped prompts and small diffs when they reduce unnecessary context and rework. Do not use an AI-generated benchmark as a substitute for measuring your own tasks.

Reliability depends on reproducible context and validation. Keep deterministic tests and CI as the merge gate, make agent actions inspectable, and provide a way to stop or roll back changes. For browser capture, network-dependent pages can fail or remain dynamic; specify a meaningful wait condition and avoid treating a successful image response as proof that the underlying page is correct.

Security and governance are lifecycle concerns. NIST’s preliminary DevSecOps work emphasizes continuous security monitoring and improvement in the context of secure software development practices. Treat it as draft guidance and verify its status before relying on it as policy. NIST NCCoE project.

9. Further reading

For a book-length introduction, SAP PRESS lists AI-Assisted Coding: The Practical Guide for Software Development (2025 paperback, 395 pages), covering tools and tasks including code generation, debugging, refactoring, testing, and documentation. SAP PRESS book page.

10. Frequently asked questions

Does AI-generated code need to be disclosed?

Follow your employer, client, project, and tool policies. Requirements differ by organization and context; establish a consistent team rule before work begins.

Can an AI assistant replace code review?

No. Automated suggestions can help reviewers find issues, but they do not take responsibility for architecture, product behavior, or release decisions.

Should a team let an agent merge its own changes?

Set merge authority according to your risk and governance model. Keep required tests and review controls in force for changes that can affect users, data, or security.

Which tool should a beginner start with?

Start with the assistant already supported in your IDE or repository workflow, on a low-risk task with clear acceptance criteria. Evaluate the review burden and controls before expanding access.