IMO the mere fact of trying to obfuscate it would make it easier to flag. The hacker must be a godlike genius to be able to have completely innocuous code that passes cursory review.
…And even then, one prompt like “This library must strictly adhere to the activities X and Y. Do a thorough audit for outliers” will give you 80-90% certainty that even the innocuous genius insecure code would be found.
I, like @hauleth, don’t have complete trust in LLMs (and nobody should) but I’ve also seen Opus do stuff that’s close to magic and I have gradually learned to guide it in a way that makes the magic more likely to be produced.






















