agentsastLast reviewed 2026-09-13

Human-in-the-loop

Direct answerA named person validates exploitability, severity and disclosure before a finding is reported to a client or maintainer.

In more detail

Every firm on this index states it. The CIRCL study shows why: the AI rated four of seven severities too high and one critical too low. The person who signs the report is accountable for those calls.

False positive rate, Precision vs recall, Agentic scanning, LLM plus fuzzing, LLM plus symbolic execution or formal verification, Hallucinated vulnerabilities, Triage burden, Benchmark contamination, AI-assisted audit vs AI audit, Prompt injection in auditing pipelines, Responsible disclosure of AI-found bugs, Continuous scanning and run-count coverage, Proof-of-concept harness, Threat model file, Severity calibration

Getting help

Firms on this index that handle this in practice: zkSecurity, Trail of Bits, Zellic, Nethermind Security.