Experts debate code eval standards: dynamic proof required

moyix · x · 2026-08-27

moyix commented that when evaluating if models "can find vulnerabilities from source code alone," the standard of evidence should match real assessments: can the PoC trigger on a live site?

The replier agreed, noting that the XBOW project prioritizes reporting only findings that can be proven dynamically, rather than guesses from static analysis.

Related event: XBOW Author Explains Philosophy of Verifying Real Vulnerabilities(2 posts)→

Original post →

More from Safety

Safety channel →