Claude-copy – Copy Claude Code output to clipboard
Reads ~/.claude/ JSONL directly instead of terminal scraping, works with Kitty and iTerm2.
OSS clone of Anthropic’s Mythos harness to locate C/C++ memory vulnerabilities
Student script found a zero-day using Claude Code and ASan automation.
Security researchers, C/C++ developers
Semgrep · CodeQL · Anthropic Mythos
From the report, it ranks every file by “how sus it sounds,” loops over each with curt instructions to “find a bug,” hands candidates to a judge + ASan checker— and zero-days simply pop out.
That should not work.
But it does.
On miniupnp with a $20 plan, Opus 4.6 reliably rediscovers known CVEs in older versions and even surfaced a new remote global buffer overflow (non-default config).
So what happens if the harness is actually good—i.e. equipped with proper security tooling?
I’m a student, not a security engineer, so I'd would love ideas or critiques on my planned tool roadmap. (If you have a $200 plan with extra usage lying around, try it out to see if it churns a zero-day in your own C)
Reads ~/.claude/ JSONL directly instead of terminal scraping, works with Kitty and iTerm2.
Bring your own API key to scan for bugs before bad actors find them.
Fixes Claude Code's messy clipboard without touching other apps.
AI trading harness with approval boundaries and audit logs for Claude agents.
Self-hosted CVE triage for Kubernetes teams stuck between Trivy CLI and six-figure SaaS.
Review mode filters false positives before escalating to humans.