Build Your Own Vulnerability Harness for Enterprise AI Security

Build Your Own Vulnerability Harness for Enterprise AI Security

We moved beyond single-model security skills to build a model-agnostic harness that treats AI as interchangeable components. By orchestrating distinct models for discovery and validation, we eliminate false positives and trace vulnerabilities across entire code fleets. This approach ensures our defenses adapt to market shifts without relying on any specific frontier model.

The harness is the bit that lasts.
  1. atgreen

    VISA open sourced an expense-to-run harness they developed under glasswing, and I used that as the basis of a skill that I've found to be pretty effective with Claude Code: https://github.com/atgreen/secscan-skill

  2. alberth

    Dumb question: Can someone help me understand whag it means to have a “harness” for agents (and why you need one)?

    I’ve done some reading on the topic and am just not getting it.

  3. mappu

    The off-the-shelf player in this space (structured red-team search) is probably https://github.com/usestrix/strix (no affiliation). But any frontier model, if you tell it "here's how the authentication system works, go looking for bugs" will probably do a good job.

More from this day

2026-07-10