> Well, how do you verify any bug?
You do or you don't.
Recently we've seen many "security researchers" doing exactly this with LLM:s [1]
1: https://www.theregister.com/2025/05/07/curl_ai_bug_reports/
Not suggesting you are doing any of that, just curious what's going on and how you are finding it useful.
> But the false positives involve the exact same cycle you do when you're looking for bugs yourself.
In my 35 years of programming I never went just "looking for bugs".
I have a bug and I track it down. That's it.
Sounds like your experience is similar to using deterministic static code analyzers but more expensive, time consuming, ambiguous and hallucinating up non-issues.
And that you didn't get a report to save and share.
So is it saving you any time or money yet?