@dangoodin LWN has an interesting article on this. https://lwn.net/SubscriberLink/1070698/f0546e940e1ed08d/
One takeaway from both articles is that these tools can be used for good or bad, and that the LLM will only look for what it's told. Evaluation and fix is drinking from the fire hose, and while one team reports zero false positives, another may find a bigger number.
Is this help or an attempt to kill free software?