Known-Bad Names, Unknown-Bad Uses: What Local Code Models Detect When They Review Cryptographic API Misuse
Small code language models are now easy to run on a developer's own laptop, and one thing people ask them to do is a quick security pass over code before it ships. I wanted to know how far that trust holds for one narrow but dangerous flaw family, cryptographic API misuse. I built CryptoBench, a set of thirty-six vulne...