I think it's actually interesting how you can use the same model to both find and falsify the findings
you can, but it's better to use a different model or higher effort level at the very least to do the verifying part. (haven't checked to see what it is they are doing exactly), but doing vulnerability validation with the same model and effort you used to find the vulnerabilities isn't going to be a true second set of eyes and the model will likely always just try and justify it was right in the first place. ime, it's…
Re: VulnHunter: Capital One's agentic AI code security tool
#41[flagged]