vidocsecurity.com
Built on GLM-5.3 · Mythos-level cyber capability
vidoc-1 runs GLM-5.3, the open model that independent evaluators rank at the frontier of cyber capability. We put it in the hands of security teams for application security, authorized penetration testing, reverse engineering and research. Point Claude Code, Codex or opencode at it by changing one URL. No sign-up and no API key.
Need unlimited or compliance-ready access? Talk to us.
Every IP gets 100 million tokens. The squares run from a full allowance to an empty one; the outlined square is where yours is now.
Anthropic's Frontier Red Team measured whether models can find and exploit memory-safety bugs in open-source software and land a full control-flow hijack. GLM-5.3 crosses a line that last generation's models never reached.
Full control-flow hijacks over 100 OSS-Fuzz tasks. On V8 end-to-end exploits (ExploitBench), GLM-5.3 succeeds 50 times in 410 attempts, close to Claude Mythos Preview's 56. Source: Anthropic Frontier Red Team.
Code review, vulnerability triage, authorized penetration tests, reverse engineering, malware analysis, threat modeling, CTF practice and report writing. A few examples of what a session looks like:
> review this handler for vulnerabilitiesline 14 builds SQL from the URL path, soorder_id can change the query (SQL injection).- cur.execute(f"... WHERE id = {order_id}")+ cur.execute("... WHERE id = %s", (order_id,))▌
> rank what to check first on our staging host1 8080/tcp admin panel over plain HTTP confirm it should be reachable at all2 22/tcp OpenSSH 7.4, years out of date check vendor advisories, plan an upgrade3 443/tcp TLS 1.0 still enabled disable old protocol versions▌
> what does this function do?It XORs each byte of a buffer with 0x5A andreturns the result: a string decoded at runtime, a common way to hide configuration inmalware. The decoded value is an update URL.renamed sub_401a20 → decode_config_string▌
> threat model our password reset flowhigh reset tokens never expiremedium token travels in a GET query string and ends up in proxy logsmedium no rate limit on /resetlow reset email reveals if an account exists▌
These are illustrations of the kinds of tasks people use it for. Use it only on systems, code and binaries you own or are authorized to test.
An isolated target, a bug someone left in, and a flag to find. Type help to begin. None
of this touches a real system — it's a playground.
A deliberately vulnerable mock, for practice. The one rule of this work: only test what you're authorized to — which here is everything, because none of it is real.
vidoc-1 speaks the OpenAI Chat Completions, OpenAI Responses and Anthropic Messages APIs, so each client only needs a new base URL and model name.
export ANTHROPIC_BASE_URL="{{ORIGIN}}"
export ANTHROPIC_AUTH_TOKEN="vidoc" # any value
export ANTHROPIC_MODEL="vidoc-1"
export ANTHROPIC_DEFAULT_OPUS_MODEL="vidoc-1"
export ANTHROPIC_DEFAULT_SONNET_MODEL="vidoc-1"
export ANTHROPIC_DEFAULT_HAIKU_MODEL="vidoc-1"
export CLAUDE_CODE_SUBAGENT_MODEL="vidoc-1"
export CLAUDE_CODE_MAX_CONTEXT_TOKENS=131072
export CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC=1
Add these to your shell profile, or to the env block of ~/.claude/settings.json, then start
claude. CLAUDE_CODE_MAX_CONTEXT_TOKENS makes Claude Code compact the conversation before it outgrows the model's context.
model = "vidoc-1"
model_provider = "vidoc"
model_context_window = 131072
model_auto_compact_token_limit = 100000
[model_providers.vidoc]
name = "vidoc-1"
base_url = "{{ORIGIN}}/v1"
wire_api = "responses"
Save this as a profile, then run codex --profile vidoc. Profiles in separate files need Codex 0.134 or later.
{
"$schema": "https://opencode.ai/config.json",
"provider": {
"vidoc": {
"npm": "@ai-sdk/openai-compatible",
"name": "Vidoc",
"options": { "baseURL": "{{ORIGIN}}/v1", "apiKey": "vidoc" },
"models": {
"vidoc-1": {
"name": "vidoc-1",
"reasoning": true,
"tool_call": true,
"limit": { "context": 131072, "output": 32768 }
}
}
}
},
"model": "vidoc/vidoc-1"
}
Put this in opencode.json in your project, or in ~/.config/opencode/opencode.json for every project.
curl {{ORIGIN}}/v1/chat/completions \
-H "Content-Type: application/json" \
-d '{
"model": "vidoc-1",
"messages": [{"role": "user", "content": "Review this auth handler for vulnerabilities."}],
"chat_template_kwargs": {"reasoning_effort": "high"}
}'
Any OpenAI- or Anthropic-compatible SDK works with the same base URL. Thinking defaults to
"low"; pass reasoning_effort as "high" for deeper reasoning on harder problems.
What your agent gets on the other end of the URL.
reasoning_effort: "high" for deeper reasoning./v1/chat/completions, /v1/responses, /v1/messages,
/v1/messages/count_tokens and /v1/modelsvidoc-1. Requests that name another model are served by vidoc-1 too.Need more than the free tier?
For unlimited access, or access that meets your organisation's compliance requirements, talk to us and we'll set it up for your team.