https://archive.ph/2025.02.14-132833/https://www.404media.co...
https://archive.ph/2025.02.14-132833/https://www.404media.co...
That's currently how I model my usage of LLMs in code. A smart veeeery junior engineer that needs to be kept on a veeeeery short leash.
LLMs are an eternal intern that can only repeat what it's gleaned from some articles it skimmed last year or whatever. If your expected response isn't in its corpus, or isn't in it frequently enough, and it can't just regurgitate an amalgamation of the top N articles you'd find on Google anyway, tough luck.
[1] https://en.m.wikipedia.org/wiki/Model_collapse
[2]https://thebullshitmachines.com/lesson-16-the-first-step-fal...
You can't do the same way you do with a human developer, but you can do a somewhat effective form of it through things like .cursorrules files and the like.
Maybe they used Grok ;P
Not my experience at all. Every LLM produces lots of trivial SQLI/XSS/other-injection vulnerabilities. Worse they seem to completely authorization business logic, error handling, and logging even when prompted to do so.
Smells like getting a backdoor in early.
I don't see any CRUD endpoints for modifying the database
https://doge.gov/workforce?orgId=69ee18bc-9ac8-467e-84b0-106... is what's linked to by the "Workforce" header, and it now looks different than the screenshots
BTW, I spent a lot of my career configuring load balancing, caches, proxies, sharding, and CDNs for Plone (a CMS that’s popular with governments) websites.