Skip to main content

Netskope details two experiments using frontier AI to test its code

Netskope’s security red team describes two sandbox experiments that use frontier AI models to test the company’s own product code, including work to reproduce memory corruption failures. The findings matter to enterprise security leaders because vulnerability research workflows depend on how evidence is generated and validated.

Research Overview

The episode features Mohit Kulamkolly, a senior engineer on Netskope’s security red team, discussing experiments where frontier AI models were directed to analyze Netskope code. The discussion includes explanations of what memory corruption bugs are and why they remain difficult to identify.

Two different experimental approaches are outlined: one uses isolated sandbox laboratories to look for crashes, and another experiment gives the AI more control while still verifying results. The verification in the second approach is described as being performed by a separate AI system.

Key Findings

The episode frames a limitation in relying on a model’s own statement that it has found a bug, rather than validating the claimed outcome through observed behavior. This emphasis on verification is linked to how the experiments were designed.

It also discusses how sub-agents can keep the search activity continuing for days without ending the effort, according to the episode’s description of the process. The episode further ties these behaviors to how evidence is collected during the hunt.

Technical Breakdown

One experiment is described as using isolated sandbox labs so that AI-driven testing could hunt for crashes. The framing includes a discussion of memory corruption as a class of vulnerability that can involve dangerous failure modes.

A second experiment is described as giving the AI more control during the testing process, with the resulting findings checked by a completely separate AI system. The episode presents this as a way to reduce reliance on a single system’s claim.

Operational Impact

The episode addresses implications for security teams without direct access to frontier models, describing how such teams might still structure vulnerability research activities. It also links the vulnerability discovery process to the broader need for remediation planning.

According to the episode, finding vulnerabilities is only part of the work without a remediation plan that follows from the results. The discussion positions early integration of AI into threat modeling and product work as more useful than using it after problems are identified.

Overall, the episode outlines how Netskope’s red team tested its own code with frontier AI models using sandbox-based crash hunting and more controlled experiments with independent verification, while emphasizing limits on trusting model assertions and the need for remediation planning; Blog Signals brief is a fact-based summary of the vendor blog.