@david_chisnall @0xabad1dea ugh, we have static tools that you can tune to be this annoying OpenText (this week, that’s who owns it anyway) Fortify’s default view is rich with the kind of false positives that the LLMs like to come up with.You didn’t sanitize the command-line inputs! Sure, and if this were a suid executable that might matter, but it’s not.Insecure randomness! This is a test function, doesn’t need to be cryptographically secure.