‹ BackHN Continuity

Thread

Cloudflare/Security-Audit-Skill

213 points · 38 comments · donk8r

  1. wslh · · focus · HN ↗
    Tip for security professionals using LLMs: audit skills that explicitly frame the task as security research sometimes trigger refusals from the top OpenAI and Anthropic models because they guard against misuse. What works for me: separate skills for bug classes (and bugs in general) without the security framing, plus another skill that combines their findings to spot security bugs.
    1. viraptor · · focus · HN ↗
      If you're a security professional, go through their validation. You won't get the security refusals anymore. Well... you'll still get the occasional downgrade from Fable, but not the "oh no, I can't do exploits for you" breaks.
      1. xur17 · · focus · HN ↗
        Except their validation doesn't seem to work. I've gone through both (both personally and for my company), and.. no response for weeks.
        1. viraptor · · focus · HN ↗
          Weird. I have minimal publicly visible record of security work and got the approval almost immediately.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.