@AutoFynAgent found 5 vulnerabilities in @nextjs@MetaMask and pnpm in one week. Two of the vulnerabilities were under active investigation and AutoFyn independently discovered them. We did all of this with just Claude Opus! Come talk to us to secure your project!
@BytedanceTalk 6/ Audit done with AutoFyn, our open-source security auditor. All 25 findings were CONFIRMED against a live instance. 11 advisories filed. Full report drops after patches. https://t.co/1kgwxU1sdd
1/ We audited Agent TARS (@BytedanceTalk ) with AutoFyn and found 25 vulnerabilities and 20 exploitable attack chains. 4 Critical, 18 High, 3 Medium. Everything disclosed privately to the ByteDance team already.
@BytedanceTalk 4/ Best practice: run Agent TARS in a container and don't store sensitive API keys in environment variables. The blast radius of any bug in the agent layer is your whole machine.
@warpdotdev AutoFyn runs @claudeai in RL-inspired loops to optimize measurable goals — security audits, benchmark optimization, bug sweeps. Each round learns from the last. Developing open source:
https://t.co/H9H9S9hm3x
We audited @warpdotdev with @AutoFynAgent and found 30 vulnerabilities and 3 critical attack chains. All responsibly disclosed; CVEs were assigned. Full report drops after the patch. What used to take weeks now takes only hours using AutoFyn.
@NousResearch@ComfyUI Hermes agent, at its current state, almost trivially allows an attacker to take control of a user's machine. We found 35 vulnerabilities and 18 attack chains. https://t.co/9grcWgnT7z
1/We audited Hermes agent (@NousResearch) with autofyn and found 35 vulnerabilities and 18 exploitable attack chains. Everything disclosed privately to the Nous team already.
@NousResearch 6/ Audit done with AutoFyn, our open source security auditor. All findings were CONFIRMED against a live instance. Full report drops after the patches https://t.co/H9H9S9hm3x
1/We audited Hermes agent (@NousResearch) with autofyn and found 35 vulnerabilities and 18 exploitable attack chains. Everything disclosed privately to the Nous team already.
@NousResearch 5/ Best practice: run Hermes in a container until the next update. Hermes has shell access, file access, and env vars with your api keys. The blast radius of any bug in the agent layer is your whole machine.