@OpenSats here’s an idea. You should create a fund for FOSS project developers to fund security disclosure evaluations. It’s great the red team exists and will be funded to find the vulnerabilities. But then the project developers have to evaluate, harden, and build tests to prevent regressions. Frontier models aren’t useful to evaluate the findings often because they get blocked.
Many of the disclosures are false positives, and it takes time to complete the evaluation. Having access to Kimi K3 would make this faster, but isn’t cheap. Most FOSS projects run on donations and individual contributions.
If there was a simple and straightforward application process for well-known actors/projects to subsidize/reimburse Kimi K3 usage for security disclosure evaluation and verification, it would be helpful.