PortSwigger's old HTTP Request Smuggler was already good at turning weird parser splits into repros, so the win here seems to be coverage and triage rather than some magic new class of bug. I’d still trust a boring grammar fuzzer plus a corpus of known smuggling patterns more than an LLM for the actual finding part, but if it can surface an Apache ATS zero-day that way, fair enough.