As soon as a new model drops I point it at one codebase I have and ask it to do a security audit, look for bugs, check for optimizations, things that are over-engineered, etc.
Every single time I've done this it has found at least one serious bug or security hole.
Makes me wonder how many are left I've not found.