Did they prompt it to consider security weaknesses?
(could be quite real!)
But security ultimately requires comprehension, which is not something LLMs have.
I think your point is otherwise right, but the correct answer is standard best practices which is the easiest thing for bots to do
It’s perfectly reasonable to not use secure code for a large number of use cases.
[proceeds to simply refactor the same code]