@drwhax the thesis here seems to be that a new threat vector – LLM-based bad actors – puts otherwise stable systems at risk. The recommendation appears to be to employ these same LLMs in an attempt out flank the bad actors.
While I am not entirely opposed to well reasoned application of LLMs and associated tooling and harnesses to a problem, I question whether a strategy based on matching rather than one-upping the bad actors is a viable one.
There is certainly value in adapting the security model of many projects, but it’s less clear to me that simply “running an LLM” over a codebase is the answer.