Interestingly, I see Daniel from curl has recently been saying the problem of clearly slop vulnerability reports has largely dried up, and the majority of A I assisted bug reports are now reasonably high quality.

I wonder if that's a natural progression when AI users and tools first start to get involved in something, or if it's more that the curl codebase and maintainers/contributors are special and unusually high quality, so there's little left to find by people with little understanding prompting tools trhey are incapable of judging the results generated?