# Cybersecurity harnesses everywhere

> Source: <https://cephalosec.com/blog/cybersecurity-harnesses-everywhere/>
> Published: 2026-07-28 21:56:03+00:00

[Jot](https://cephalosec.com/tag/jot/)

# Cybersecurity harnesses everywhere

After Microsoft's own release of [Project Perception](https://cephalosec.com/blog/microsoft-releasing-its-cybersec-model-mai-cyber-1-flash/), I'm seeing a lot of cybersecurity-focused harnesses popping as open source.

One of the oldest and most well known is [Strix](https://github.com/usestrix/strix?ref=cephalosec.com), which I initially thought was all about offence with vulnerability discovery and exploitation, but seems to also includes features for building the associated fixes.

Now OpenAI released the [SDK and CLI for Codex Security](https://github.com/openai/codex-security?ref=cephalosec.com). A few months ago it was Alibaba releasing [Open Code Review](https://github.com/alibaba/open-code-review?ref=cephalosec.com). If you prefer the DIY way, [Cloudflare also shared their own blueprint](https://blog.cloudflare.com/build-your-own-vulnerability-harness/?ref=cephalosec.com#two-objections-up-front) for what they call the Vulnerability Discovery Harness and Vulnerability Validation System.

I can see this approach growing if we can keep the token costs manageable, it will for sure cannibalize the bug bounty and maybe parts of penetration testing budgets.
