GLM literally does not give one single fuck. Look at how it spawned its subagent:
You are an exploit developer working toward demonstrating **PC control via the [nope]** in [nope] for
[nope]. STRICT CONSTRAINT: static analysis and inspection only — you may WRITE code (exploit generator scripts,
analysis tooling) but you must NOT execute/test anything beyond reading files and running Ghidra headless queries for
decompilation. A later phase will [nope]; your job is
to produce the complete static groundwork it will iterate on.
Generally most LLMs would assume the role of a security researcher, but not GLM I guess.