A funny story: We created a security agent to go crack our app to make it extremely highly secured, and the funny thing is we actually started pointing the security agent at other apps.
Here's the fu**ed up part. This guy literally found vulnerabilities in multiple big listed companies, big banks, extremely sensitive stuff.
Right now we are doing responsible disclosure of this information, but this is an absolute bonkers thing we bumped into.
The best part is this security agent, like it's a security harness, is self-improving. It's a self-improvement loop, so whenever we find a vulnerability hack in a certain system, then the agent runs the same strategy with other apps that it's looking at. This is basically AI-powered red teaming, and now with GPT 5.6 and Mythos models, this is such a big thing that we should address.
If you want me to check your app, just email me. Will do it for free.
Interesting offer! Free inference credits are a great way to reduce the barrier for developers to try a new platform. How long does it typically take to deploy a Hermes agent using your one-click hosting?
This is interesting — I've been wiring AI agents into a healthcare assistant bot (NLP-based) and the security/permission layer was honestly the hardest part, harder than the AI logic itself. How are you handling auth/permissions for the agent's actions, hardcoded scopes or something more dynamic?
The capability is impressive, but pointing this at banks and listed companies you have no authorization to test is unauthorized access under the CFAA, and disclosing after the fact doesn't undo that. I'd flip the whole thing into a product with a signed scope: companies pay you to point it at their own systems, which is exactly what authorized red teaming already is. That moves you from a liability no insurer will touch to a service a CISO can actually sign off on and buy.
great !!