Developer SecFathy open-sourced a research prototype called XSS Specialist, an 8B security model designed for XSS vulnerability analysis. The project initially aimed to push specialization limits using retrieval and LoRA but ultimately rejected the model because it failed adversarial near-miss tests where small identifier changes caused incorrect safety judgments.

  • The developer redesigned the system to separate reasoning from truth establishment, moving confirmation authority to an independent execution layer.
  • A potential XSS finding is only confirmed when a real headless browser executes a benign sentinel.
  • On a frozen 102-case live benchmark, the resulting architecture achieved 94.1% precision and 100% recall with zero false negatives.
  • The code, architecture, benchmarks, and negative results are available on GitHub under SecFathy/xss-specialist.

The author argues that reliable AI systems should be designed to remain functional even when the model is wrong, rather than depending solely on making the model trustworthy.