Claude Security Audit

Since Fable 5 was re-enabled and made available in the app on weekly usage limits until July 7th, has anyone pointed it to the GitHub - hestiacp/hestiacp: Hestia Control Panel | A lightweight and powerful control panel for the modern web. · GitHub repo to perform a security audit, as it’s really good at it?

I am actually looking into this and probably tomorrow have the time to send it on a hunt…

just as a quick follow up: Fable5 flags attempts for such kind of audits right from the start.

Fable 5’s safeguards flagged this message. The safeguards are intentionally broad right now and may flag safe and routine coding, cybersecurity, or biology work. These measures let us bring you Mythos-level capabilities sooner, and we’re working to refine them. Switched to Opus 4.8.

and that was on only trying to plan some audit, not even doing it.

I am working on reviewing the code base with AI support nevertheless already, but seems right now there will be no simple fable5-does-it-all version of such audit :frowning:

Bummer… Then I guess Opus will have to do. :disappointed_face:

Anyway, it should be good enough for most audits, but security should be the top priority.

Thanks for your support @falzo

And some good news: ClaudeDevs on X: "6 months of Claude Max 20x, on us. We're expanding Claude for Open Source to more of the community. If you're a maintainer, a core contributor, someone landing PRs across the ecosystem, or someone keeping a critical package alive, apply today! https://t.co/F4bB61z673" / X

While this is nice, the criteria are rather tough: Claude for Open Source | Claude by Anthropic | Claude

I don’t think anyone of us can match that.

On another note: Opus did not find anything serious. (at least based on my prompting)

I will review the output and forward internally.

But I am also refactoring HestiaCP right now into an own fork, so if anything critical pops up during this, it will also be taken care off :wink: