In the past years, I’ve witnessed a new character appear in the open-source ecosystem: what I call the ‘Vibe security researcher.’ Not a security engineer, not a contributor, but someone who points an AI agent at popular repositories, waits for it to flag any theoretical glitch, and then publishes...
