A security firm just did what OpenAI's and Anthropic's tools reportedly could not: find six bugs in curl.
Aisle, a security research outfit, says it audited curl, the widely used command-line tool and data-transfer library, and turned up six vulnerabilities. According to Aisle's account, OpenAI and Anthropic had already reviewed the same codebase with their own tools and reported finding zero issues. The claim first appeared as a blog post, then reached Hacker News, where it collected 60 points and 22 comments. The available summary does not include CVE identifiers, severity ratings, or the curl version tested, details that would let outside engineers actually verify the claim.
curl runs inside nearly every operating system, router, and internet-connected app, so a six-bug gap is not trivial if it holds up. The more interesting story is what it implies about AI-assisted code review: two well-funded labs' tools reportedly missed everything that a smaller, human-led audit caught.
Until Aisle or the curl project publishes the technical writeup (patch notes, CVE numbers, proof-of-concept code), treat "zero" as an unverified claim about AI tooling and "six" as an unverified claim about curl. Neither number means much without the paperwork.