A security ruleset is judged by what it does not flag. Anyone can write a pattern that catches a vulnerability. The difficulty is catching it without also catching the ten correct implementations that look similar.
Source: [Dev.to](https://dev.to/catidegla/two-security-rules-i-wrote-and-deleted-and-why-the-second-one-was-worse-4439)