Well, they should point users to a project responsible enough to accept huuman reviewed security and bug fixes that happen to have been written by an llm.