What I find interesting about this one specifically is how text-native vulnerability research already is. Reading code, reading docs, pattern matching on known bug classes, it's almost the ideal task for a linguistic intelligence. The text distance was always close here.