Skip to content
Hacker News front page

Cosine ships ArgusRed: a post-trained model that pen tests instead of refusing

Show HN: We post-trained a model that pen tests instead of refusing

Cosine post-trained its coding model to do security scanning and authorized pen testing from a single CLI. Security Scan is read-only; Pen Test runs real exploits but requires booking and signed authorization. Free install includes 2M tokens. A Symfony scan (~1.5M LOC) took ~40 minutes. The post doesn't disclose the base model, the post-training recipe, or any benchmark comparisons.

Why it matters: Cosine post-trained a coding model into a pentesting CLI — the refusal-to-attack pivot is newsworthy, and the dual-mode permission design adds substance. Score held at 72 because it's a fresh product launch with no independent benchmarks or user reports yet, and the post doesn...

Read the original ↗Export Markdown