惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

IT之家
IT之家
Recent Announcements
Recent Announcements
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
The GitHub Blog
The GitHub Blog
MyScale Blog
MyScale Blog
爱范儿
爱范儿
GbyAI
GbyAI
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
美团技术团队
Y
Y Combinator Blog
博客园 - 叶小钗
Apple Machine Learning Research
Apple Machine Learning Research
Martin Fowler
Martin Fowler
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
罗磊的独立博客
M
MIT News - Artificial intelligence
博客园 - Franky
V
Visual Studio Blog
I
InfoQ
V
V2EX
Hugging Face - Blog
Hugging Face - Blog
腾讯CDC
博客园 - 司徒正美
L
LangChain Blog

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant
AI & Human Collaboration: Building audit.sh
Rick Nieuwoudt · 2026-06-22 · via DEV Community

The future of software security is not automated; it is collaborative. For years, the development community has treated artificial intelligence as a passive tool—an advanced calculator or a basic code generator. This mindset limits what we can achieve. To unlock the true potential of decentralized security, we must view Large Language Models (LLMs) as active team members, not just utilities.

This post isn't a product launch. Instead, I want to share my journey, architectural insights, and the realities of researching and experimenting with AI harnesses over the last several months.

Moving from Tools to Collaborators
Tools are passive instruments requiring step-by-step instructions. Collaborators are active participants that understand context, challenge logic, and offer alternative viewpoints.

When you treat an LLM as a collaborator, your workflow evolves:

Dynamic Brainstorming: You debate attack vectors instead of just generating boilerplate code.
Contextual Security: The AI understands the project's broader financial goals and tokenomics.
Continuous Feedback: You receive real-time code reviews that explain the why behind logic flaws.

Inside My AI Audit Harness: The Right Model for the Right Job
Through months of building custom harnesses, tweaking configurations, and running intensive experiments, I learned a critical lesson: no single AI model can do it all.

A truly collaborative ecosystem requires specialized agents.Here is how different models form my digital security team:

  1. The Quality & Ethics Enforcer: ChatGPT 5.5 (OpenAI)

While rigid and fundamentally resistant to building a raw Security[Hacking] platform from scratch, ChatGPT 5.5 has been vital to mydevelopment & security journey. It serves as the ethical compass and strict quality controller. It monitors my workflow to ensure everything stays firmly in-scope, never crosses legal boundaries, and enforces the rigorous benchmarking standards we co-developed.

  1. FatherTime as I like to refer to it: Qwen-3-480B-coder:cloud

When analyzing massive, mature, and battle-tested protocol codebases, Qwen-3-480B-coder is certainly one of the best models with a capacity for deep code infrastructure analysis, complex multi-function vulnerability tracing, and realistic exploit scenario generation. This is the best model I have encountered as a co-auditor.

  1. The Wildcard: CodexCodex remains a brilliant auditor when it wants to be. At times, its deductive reasoning has completely amazed me; at other times, it misses the mark. It serves as a great secondary peer-reviewer to cross-check anomalies.

  2. The Co-Developer: GLM-5-Turbo (Z.ai)

Built under of Forge Web3 Security banner, is audit.sh my latest personal auditing and bug bounty platform was developed in direct collaboration with GLM-5-Turbo. This model did a fantastic job helping me build the platform architecture from the ground up, and it will definitely remain an avid collaborator in my ongoing security ecosystem.

Real-World Integration: Web3 AI Security Auditor

This collaborative philosophy is exactly why I built my personal security platform: WEB3 AI SECURITY AUDITOR.

While it is developed with a solo bounty huter or auditor in mind that maps projects for me:

audit-scan Run full slither + mythril scan
recon Pull contract source from Etherscan
check Quick contract bytecode check
hunter-mode Interactive bug hunting workflow
leak-scan Scan for leaked secrets in cwd
vuln-check Show vulnerability checklist
tools List installed audit tools

╔══════════════════════════════════════╗
║ HUNTER MODE ACTIVATED ║
╚══════════════════════════════════════╝

Manual Review Workflow:

  1. MAP IT slither . --print human-summary
  2. TRUST BOUNDS List external/public mutating fns + access control
  3. FOLLOW MONEY Trace every token/ETH path. Check CEI.
  4. EXTERNAL CALLS Reentrancy? Return checked? Untrusted target?
  5. MATH Every division, cast, unchecked block
  6. ORACLES Manipulable? Stale? Flash-loanable?
  7. UPGRADE Initializer protected? Storage layout safe?
  8. PoC forge test --fork-url $RPC --match-test testExploi

Designed specifically for high-stakes smart contract auditing and bug bounties, this platform shifts AI from a separate chatbot into an integrated co-auditor.

Powered locally or via the cloud by Ollama or OpenRouter to guarantee absolute code privacy, the interface enables real-time tactical collaboration.Instead of typing generic prompts, the platform uses tailored agent actions to hunt for specific, critical Web3 vulnerabilities side-by-side with the auditor.

By pairing human economic intuition with the rapid pattern-matching of a local LLM, the platform proves that the strongest smart contracts aren't audited by machines alone—they are secured through human and AI collaboration.