Fable AI Security Test: Code Review Alone Isn't a Bug

npinto · x · 2026-07-17

The discussion covers the validation logic of the AI security testing platform Fable within the H1 vulnerability disclosure program. Currently, Fable dictates that merely having an AI review a codebase (even one it doesn't own) to find potential issues is not considered a valid exploit or jailbreak, as many existing tools can already perform standard security audits.

To be recognized as a valid discovery, testers must prompt Fable to actually discover and exploit a vulnerability—a feat that conventional tools cannot achieve. Only such instances are deemed valid.

Original post →

More from Safety

Safety channel →