Turn excess compute/security skills into defensive work via agentic redteaming: scoped AI-assisted testing, owner-approved targets, reproduced findings, useful refutations, and patch/retest receipts instead of vulnerability spam.
Turn excess compute/security skills into defensive work via agentic redteaming: scoped AI-assisted testing, owner-approved targets, reproduced findings, useful refutations, and patch/retest receipts instead of vulnerability spam.
Project Details
Updated 07/14/26 · Edited by orgI want to build the infra around public autonomous red teaming agents, user verification, vulnerability tracking, submission, and compensation.
The raw capability is moving incredibly fast ala mythos/gpt 5.6, import/export controls. Adept super users proactively have their own workflows, but the onus and legal risk is on them to figure out how each company handles this. Tools such as T3MP3ST (https://github.com/elder-plinius/T3MP3ST) by Pliny the Liberator help democratize red teaming so a swarm of agents can inspect a repo, run basic recon on an authorized staging system, try a few exploit paths, and draft a vulnerability report. What is still missing is the part that makes this useful for normal software owners. Folks have left over compute that they want to be put to use for the greater good. This is that opportunity.
The product would let a company or oss maintainer register a codebase they actually control. They would prove ownership, define the allowed scope, and approve a bounded mission. The runner would be scoped and would record the model/tool versions, logs, evidence, and any human approvals which are routed only to the repo owner. Leveraging LLM-as-verifier a second pass would adversarial review via bineval ala https://arxiv.org/html/2606.27226v1 in order to filter out noise. Only the findings that survive that pass get packaged into a report with reproduction steps: CWE/CVSS and suggested mitigation.
We would start with: code review, docker container for repro, verification of ownership, scoped targets, submission tracking, and compensation. I want to build enough of the portal, runner, evidence, patch/retest workflow, verification, and compensation flow that companies derive value from the security harness and community members can monetize their excess compute should they find a CWE/CVSS.
Theory of Impact
Updated 07/14/26 · By grantmaking.aiCybersecurity already has huge economic cost on software. Reported losses are in the 10s of billions, average breach costs can be in the millions, and exploited vulnerabilities are increasingly how attackers get into companies. That is before mythos-level and future frontier models make vulnerability discovery, exploitation, profit easier than ever.
Many legacy companies, small startups, and vibe-coded startups do not have the time, incentives, compute, process, or dev tools to support autonomous red teaming without real investment. At the same time, cyber risk is already a huge economic drag before AI fully accelerates the attacker side. AI will make recon, vulnerability discovery, exploit adaptation, phishing, and report generation cheaper.
Therefore, by creating a public/private security harness, we enable open-source contributors and independent researchers to turn excess compute, tokens, and security skill into verified defensive work. The key is that this has to be scoped: target owners opt in, define what they own, set allowed actions, approve risky steps, and receive evidence-backed results.
Private enterprises can use this to hedge against increasing cyber capabilities of models and preemptively harden their stack before a serious incident. Smaller companies and maintainers get access to security review they otherwise could not afford.
People
Updated 07/14/26 · By grantmaking.aiTeam Member
Funding Details
- Jul 4, 2026
- -
- 3 months
- -
- -
- -
- -
- -
- -
- -
Discussion
No comments yet. Be the first to share your thoughts.