AI labs should sell security report cards for open-source releases
As someone who vibe-codes quite a bit having built Dorso and Pike, a problem I often see tinkerers like myself face is building trust with users for what we have built. It's not uncommon, for example, to see someone decry "I'm not going to try your slop on my machine" in subreddits like r/selfhosted.
I would encourage SOTA labs to build a product that can produce a public report card, pinned to a particular commit SHA of a project, that makes visible a full security scan by their latest model with any and all flags it produces. It should have a binary safe or unsafe demarcation.
I trust models like Fable to give a green flag - and I would be happy to spend my subscription, or even credits, giving the software I build a green flag to build trust with more users.