@davidgerard the main difference between “the good claude” and “the bad claude” is the “good” one takes longer to run and its output is more confident and uses more impactful words so the human operator thinks they’ll be fired if they ignore its output
that’s pretty much it. letting it run longer lets it pull more shit into its context window but at a base level the goal’s just automated manipulation.
giving the thing more resources, more scripts to run (which are godawful by the way), and a bigger model might mean its output contains more legitimate bugs
but it also contains a fuckload more illegitimate bugs, and it’s much much more confident-sounding that they’re all critical
cause that’s how fuzzing works. we’ve had it for decades.