In my experience, the issue has been likelihood of exploitation or issue severity. Claude gets it wrong almost all the time.
A threat model matters and some risks are accepted. Good luck convincing an LLM of that fact
Primarily into cybersecurity especially fuzzing and supply chain.
contact: hackernews {at} ruebezahl {dot} mozmail {dot} com