OpenSSF Finding and Fixing Vulnerabilities Using AI

5.2 Handle external findings

Handle external vulnerability reports as findings.

External people and organizations may report what they claim are vulnerabilities. Unfortunately, these reports may be false, especially if they were AI-generated (since AI may not understand the context). This means that such reports are essentially findings.

A widespread problem is “AI slop reports”, that is, reports generated by an AI that are nonsense and waste everyone’s time. There are some steps you can take to counteract this. For example:

Several prominent programs changed their policies in 2026 because of AI-generated reports. Their experience is instructive:

The lesson for your project: publish a clear vulnerability reporting policy (e.g., in SECURITY.md) that says what evidence you require (such as a reproducing input), that reporters must validate reports before sending them, and that you welcome AI-assisted reports that meet those requirements. If you offer rewards, watch whether they attract low-effort submissions. For guidance on setting up a coordinated vulnerability disclosure program, see [CISA2026-CVD].

Quiz

Q1. Per the material, what should a project’s vulnerability reporting policy say about AI-assisted reports?

  1. Reject every report that used AI at any point, since such reports are almost always false positives
  2. Accept AI-generated reports as-is, since modern models rarely report vulnerabilities that aren’t real
  3. Offer larger bug bounty rewards for AI-assisted reports, since bigger rewards attract better-validated reports
  4. Require a reproducing input and prior validation by the human reporter, and welcome reports that meet that bar
Show answer Answer: D