Proving LLM-Found Authorization Bugs in AI-Generated Code
A model can find a suspicious route. It cannot tell you whether the route is actually reachable. This paper sets out the check that decides: an anonymous role reads a planted canary row inside a single transaction that is always rolled back, and the finding only counts if that read succeeds.
Nothing of yours is read. The transaction is rolled back either way.