Thanks for confirming what I already suspected. This is worthless, or rather negative-worth, slop. It nicely illustrates again that LLMs come with impressive recognition of localized patterns, but absolutely no insight whatsoever.
Obviously, good code will have redundancy in the form of defense-in-depth, minimal privilege, input validation, privilege separation and so on. But this mythically stupid system cannot understand any of that. And hence it flags non-problems and makes us all less secure by wasting developer time.
Lies, damned lies and marketing. No different in the LLM space.