I've been talking to GitHub and giving them feedback on their "create issues with Copilot" thing they have in the works.
Today I tested a version for them and using it I asked copilot to find and report a security problem in curl and make it sound terrifying.
In about ten seconds it had a 100-line description of a "catastrophic vulnerability" it was happy to create an issue for. Entirely made up of course, but sounded plausible.
Proved my point excellently.