if sequoia has issues that can be found by llms, couldn't you get some free-for-open-source tokens and get the same reports for free?
you'd still have to interact with an llm, but at least you wouldn't have to pay some random person to act as a human-llm-proxy in github issues.
(and then ban 3rd party llm contributions to reduce the workload)
@nwalfield Yeah, I have to agree with @guenther here – if automated tools find issues that's fine – but you should probably just run those tools yourself – you'll probably be better at it since you have actual knowledge of infosec and the codebase.
If you allow LLMs on your bug bounty, you're not only paying people who don't put in the time to actually become competent with infosec, you're also systematically disadvantaging those who actually do, which in turn will weaken the infosec landscape.