Deterministic analysis vs asking a model
"Paste the repo into the model and ask it to find the security bugs" has become a common first attempt at AI-assisted security review. It is easy to try, and the first run is often impressive: the model names a plausible injection, explains it well, and suggests a fix.
The trouble starts on the second run. And the third. And when somebody asks what it did not look at.
