> Really unfortunate. I don't understand why there's such a lack of response on the Cursor side.
It's hard to vibe code security.
It's hard to vibe code security.
The general idea of a few layers of automated triage by increasingly powerful LLMs, before finally escalating to a human engineer, seems like a reasonable way to handle a deluge of submissions. It just has to be implemented well and continuously calibrated.
Conversely, running human or LLM-generated code through multiple LLMs to look for security holes is a fantastic way to increase security.