I don’t think the OP was suggesting maintainers blindly accept PRs—rather, they can just blindly reject them.

I think GP is making the opposite point.

Blindly rejecting all PRs means you are also missing out on potential security issues submitted by humans or even AI.