Gemini's current state is pretty rough for serious code auditing work. While it handles basic tasks with decent speed, using it for security reviews is like bringing the wrong tool to a critical job. The gap between Gemini and actual SOTA models is significant enough to be a real problem if you're relying on it for anything beyond surface-level checks. For devs doing security work, you're better off with models that actually understand threat modeling and vulnerability patterns at a deeper level.