AI slops from Eve: oss-security debate over LLM-generated advisories ends with moderator finding no common source
Three AI-generated posts from 'Eve', an 'automated security researcher', approved on oss-security sparked a multi-day debate (Sept 10-13, 2026) over AI slop on vulnerability mailing lists, ending with moderator Solar Designer concluding the fake advisories…
On September 9, 2026, three posts submitted by 'Eve', described as an 'automated security researcher', arrived on the oss-security list server lacking Date headers; moderator Solar Designer approved them despite uncertainty about their value, suggesting they may have historical significance as early examples of AI-generated security reports at the dawn of AI security research. Eli Schwartz replied that the submissions were incoherent or probably wrong, urged the community to stop anthropomorphizing the program, mocked the sender's 'colorfully professional' joke email domain, and argued that volunteers triaging bot reports like human correspondence is counterproductive. Subsequent replies debated grammar ('which' versus 'it') and argued AI models remain human-developed algorithms running on human-built hardware. Responding to criticism, Solar Designer said he may start rejecting repetitive AI-generated postings in his moderator role. Joe Krause then warned that mail provider cock.li houses many script kiddies and advised treating almost any email from that domain as spam; Solar Designer replied that moderation is primarily by content rather than sender domain, that no domain produces enough unwanted traffic to warrant pre-filtering, referencing a mail hosting provider claiming roughly 1.4 million users. David A. Wheeler predicted AI-enabled attacks will be painful for many over the next few years because AI greatly reduces the cost of attacks, stressed that all systems (not just critical ones) have always required defense since many who assumed they would not be attacked were successfully attacked, and noted AI simultaneously helps with finding and fixing vulnerabilities. On September 13, Jeroen Roovers asked whether a current LLM-generated message without a Date header came from the same source as a May 15, 2026 posting titled 'Security Advisory: Multiple Vulnerabilities in llama.cpp GGUF Format Parsers', noting both fake advisories shared the missing-Date-header trait. Solar Designer closed the thread by finding the suspicious messages share only trivial traits such as a missing Date header and LLM use, concluding there is no significant problem with any particular sender or model and no investigation is needed. No CVE identifiers, software versions, or exploitation details appear in any report. Sources disagree on the posts' value: the moderator saw possible historical significance as early AI-written security reports, while Schwartz judged them…
- Three AI-generated posts by 'Eve', an 'automated security researcher', were approved by moderator Solar Designer; they lacked Date headers and arrived on the list server on September 9, 2026.
- Eli Schwartz called the submissions incoherent or probably wrong, urged the community to stop anthropomorphizing the program, mocked the sender's joke email domain, and said volunteers triaging bot reports is counterproductive.
- Solar Designer said he may start rejecting repetitive AI-generated postings on oss-security.
- Joe Krause described cock.li as a mail host housing many script kiddies and advised treating emails from that domain as spam; Solar Designer said moderation is by content, not sender domain, noting no domain produces enough unwanted…
- David A. Wheeler predicted AI-enabled attacks will proliferate over the next few years because AI greatly reduces attack costs, all systems have always needed defense, and AI also aids finding and fixing vulnerabilities.
- Jeroen Roovers asked whether the header-less LLM-generated messages came from the same source as a May 15, 2026 fake advisory titled 'Security Advisory: Multiple Vulnerabilities in llama.cpp GGUF Format Parsers'.
- Solar Designer concluded the suspicious messages share only trivial traits (missing Date header, LLM use), with no significant problem attributable to any particular sender or model and no investigation needed.
- No CVE identifiers, versions, exploit code, or exploitation details appear in any report; the thread is meta-commentary, not a vulnerability disclosure.
Coverage timelineoldest first · each row is one article
- · 5d agoAI slops from Eve
oss-security· 18
oss-security moderator Solar Designer approved three AI-generated vulnerability reports from automated security researcher Eve, sparking debate over AI slop on the list.
- · 5d agoRe: AI slops from Eve
oss-security· 4
Eli Schwartz on the oss-security list criticizes AI-generated 'slop' posts from 'Eve', urging the community to stop anthropomorphizing bots.
- · 5d agoRe: AI slops from Eve
oss-security· 2
oss-security subscriber Jeffrey Walton asks posters to refer to computer algorithms as 'it' rather than personifying them as 'he' or 'she'.
- · 4d agoRe: AI slops from Eve
oss-security· 5
oss-security thread 'AI slops from Eve' continues with English grammar corrections rather than security content.
- · 4d agoRe: AI slops from Eve
oss-security· 12
oss-security commenter argues AI models remain human-built algorithms while reflecting on recent AI-slop incidents in open-source
- · 4d agoRe: AI slops from Eve
oss-security· 12
oss-security moderator Solar Designer says he may reject repetitive AI-generated postings after debate over AI slop submissions.
- · 4d agoRe: AI slops from Eve
oss-security· 5
oss-security contributor Joe Krause warns that emails from mail provider cock.li, which he says hosts many script kiddies, should be treated as spam.
- · 4d agoRe: AI slops from Eve
oss-security· 5
oss-security maintainer Solar Designer explains the list moderates by content rather than sender domain amid ongoing AI-generated spam postings.
- · 3d agoRe: AI slops from Eve
oss-security· 12
David Wheeler's oss-security reply argues AI will make attacks far cheaper and more prolific, urging defenders to protect all IT systems, not just critical ones.
- · 2d agoRe: AI slops from Eve
oss-security· 2
Mailing-list reply criticizing AI labs for offering short free compute trials to free software projects instead of real support.
- · 2d agoRe: AI slops from Eve
oss-security· 6
Jeroen Roovers links a header-less LLM-generated advisory to a similar fake llama.cpp GGUF parser advisory from May 2026.
- · 2d agoRe: AI slops from Eve
oss-security· 6
Solar Designer finds little similarity between recent LLM-generated fake advisories on oss-security beyond missing Date headers.