Damus
semisol · 2w
About this entire AI security scanning thing: 1. Why are people using $ spent as a metric? 2. A huge chunk of these vulnerabilities are likely hallucinated and/or overstated 3. You can’t just point...
Cat-Go-Purrrrrrr profile picture
$ spent is also the metric is useful when comparing to security audits and bug bounty programs (sadly already a low bar)

overstated or exagerating the impact of bugs are a thing for sure, it is still a useful tool to use can be useful as a starting point. But requires a human to verify vulns and give it a real cve rating

Third point is absolutely right, but you can train the modela and give the harness the right tooling to do the job of a team of junior vulnerability researchers

* just my 2 sats trying to use the clankers for bug hunting during the react2shell and shai-hulud disclosures
1❤️1
semisol · 2w
Well a harness that wastes tokens is a great way to maximize money spent