OpenAI recently released Codex-Security. We simplified it based on what we use in our own products and put it in the PI harness. We will release data on DeepSeek v4 and GLM-5.3 performance soon, but so far it's probably the best open-source vulnerability detection tool out there right now.
The idea is the same as Codex Security.
1. Build a threat model
2. Launch a lot of probing agents looking into the security based on the threat model
3. Deduplication
4. Validation
5. Severity and likelihood calibration
OpenAI recently released Codex-Security. We simplified it based on what we use in our own products and put it in the PI harness. We will release data on DeepSeek v4 and GLM-5.3 performance soon, but so far it's probably the best open-source vulnerability detection tool out there right now.
The idea is the same as Codex Security.
1. Build a threat model 2. Launch a lot of probing agents looking into the security based on the threat model 3. Deduplication 4. Validation 5. Severity and likelihood calibration
We did a deep dive article here on it as well https://x.com/GustavHartz/status/2084926544800035266