Generative coding tools and "security review"
06 June 2025
Recently, at work, someone mentioned that a popular generative coding tool, which will remain nameless, introduced a “security review” feature. I expressed some doubt about the value of an LLM-driven “security review” not because I don’t think an LLM can find some security problems, but because I think it’s too easy to think it can find all the security problems. I believe an important part of exposing a tool that claims to do “Security Review” is being very clear about its weaknesses and I suspected that this coding tool didn’t approach this with the subtlety and nuance it deserves.