Comment by genshii
3 hours ago
Someone could come into this post and leave a comment saying they're a security researcher, that they audited the codebase, and include a summary of their findings. And that person could be lying.
I think saying that it contributes nothing because a) someone could do it themselves, b) the output might be slop, and/or c) they could be lying, is a bit silly. Those things apply to basically everything posted on the internet.
Whether an LLM security review is actually valuable is an entirely different discussion.
Sure, though I'd be more understanding of someone with little in the way of technical chops posting "here's my alleged LLM output" than someone saying "I'm a security researcher, looks great" when they've never linked any of their publications or anything. That's why I see this as a newer, slightly more dangerous spin on the old issue. (mitigation suggestion in my sibling comment)