34 karma · joined February 15, 2024
After thinking about it for an hour I came up with this:
LLM claims that there is a bug. We dont know whether it really exist. We run a second LLM that is capable to write unit-tests/reproducer (dont have to be E2E, shorter data flow -> bigger success rate for LLM), compile program and run the test for ASAN assert. ASAN error means proven bug. No error, as you said, does not prove anything, because it may simply mean LLM failed to write a correct test.
Still don't know how much $ it would cost for LLM reasoning, but this technically should work much better than manually investigating everything.
Sorry for "have-you-ever" thing :)
Have you ever tried to write PoC for any CVE?
This statement is wrong. Sometimes bug may exist but be impossible to trigger/exploit. So it is not trivial at all.
It's almost the same as saying "you don't need a password on your phone" or something like that.
chroot is not a security tool and never has been
How is it supposed to work, if agent can simply run "cat" command instead of using skill for file read/write/etc?
LAN, Android / PCs, easy to use for non techs
no middleware and other sh..