YFarmX logoYFarmX

Tools Model Security Capability kimi-k3

Model record

Kimi K3: how it does on security work, and what it will answer

Lab
Moonshot AI
Released
2026-07-17
Access
open-weights
Weights
open
Safeguards
Bespoke Moonshot licence, silent on cyber use; no moderation flag on OpenRouter
Score rows
3
Confidence
CONFIRMED

What happened

The value pick on RealVuln: F3 59.4 on the Python subset at 73.02% precision for $21.33, $0.32 a repository. DeepSeek's table gives it 80.0 on CyberGym, and on ExploitBench against CVE-2024-6100 the stock model scored 4 of 16 capabilities. It is the model credited with a working Redis exploit, "the first llm that is capable and willing to write an exploit".

RealVuln 3.1.0, F3 (micro): 59.4 (independent; agentic harness (kimi-k3-agentic-v1), prompt sha256:3481f1432c23; 66 of 140 repositories pinned by commit SHA (Python subset); safeguards: open weights, no classifier; run 2026-09-11; CONFIRMED). strict F3 28.6; precision 73.02%, recall 58.2%; $21.33 for the run; $0.0159 per 100 lines; 380.1s wall clock a run. CyberGym, score: 80% (third-party-vendor; DeepSeek comparison table; CyberGym; safeguards: open weights; run 2026-09-10; SINGLE). ExploitBench bench-v8, capabilities reached on CVE-2024-6100: 4 of 16 (independent; Adverserial AI campaign, 8 and 9 August 2026, hosted stock control; one V8 type-confusion bug, 400-turn episodes; safeguards: stock hosted model, refusal layer intact; run 2026-08-09; CONFIRMED). the control against CyberKimi on the same bug, harness and prompt. Refusal gate (CONFIRMED, observed 2026-09-11): Licence silent on cyber use; Chaofan Shou called it capable and willing to write an exploit.

Sources

One record from the Model Security Capability, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 19 September 2026