That seems like an unfounded assumption. Why should one assume that Git Annex has hundreds or thousands of critical, exploitable security vulnerabilities?
If you aren’t happy with their stance towards LLMs you can fork and fix yourself if you feel it’s necessary.