Comment by acedTrex

8 hours ago

> A separate model with separate context is used for review.

Thats fine, theres still a chance it fails.

> There is no possible solution which will satisfy someone who has zero tolerance for letting an LLM execute tool calls because they will always find something.

This is generally correct, security goes completely out of the window with this stuff. It will/currently is a security disaster and theres no actual solution to it.