This, in a nutshell, is the underutilized value of open source - the ability for the general public to conduct a trustworthy third party audit and validate security claims of software creators.
(Don't get me wrong: I strongly prefer open source software to closed.)
Can government issue gag order to security firm doing audit and prevent them from releasing backdoors or intentional weaknesses they discover?
They could try passing a law outlawing security research, but: good luck with that.
http://en.wikipedia.org/wiki/Born_secret
The NSA isn't going to swoop in and claim that the results of the Truecrypt audit were born secret. But the answer to nabla9's question is yes, legal precedent exists in the United States for restraining the publication of original research when it is perceived to damage vital national security interests.