@cwebber@social.coop
I'm actually more apprehensive of llm-based security reviews than of code generation, because there are more problems with the former that I can't see a feasible way of solving in the current world.
Unreliable security reviews create the same kinds of issues that level 2 autonomous driving does. Even if we assume that this is not an issue during code reviews due to general poor quality of attempts to look at security during code reviews now, we have more problems caused by statelessness of the bot: adversaries can build a similar bot and search for vulnerabilities it won't complain about, and the cases where subsequent PRs worsen the situation incrementally (not necessarily due to malice: perhaps due to people doing the minimum amount of changes to make the bot "happy") are hard to deal with.
For code generation I can see areas (well specified problems or problems where we have a reliable way of scoring solutions against each other, and when the code will run sandboxed or in a way morally equivalent to sandboxing) where, with sufficient effort, one could use LLM generators safely (albeit the effort I foresee would probably negate many of the reasons people want to use them for).