Aardvarks
– Getty Images

OpenAI has introduced Aardvark, an AI-powered security researcher tool.

Built on its flagship GPT-5 model, the system is designed to help developers and security teams explore vulnerabilities in software at scale, with the ability to autonomously review massive codebases and monitor changes in real time.

Aardvark works by scanning a codebase and finding existing vulnerabilities in the repository. It then produces a detailed threat model based on defined security objectives and a project’s design framework.

image (10)
Aardvark workflow – OpenAI

Vulnerabilities are validated in a controlled, sandboxed environment, and patched through a Codex integration. Like ChatGPT, it then generates a human-readable report with code annotations and explanations for developers to review.

The AI tool is also able to identify logic flaws, incomplete patches, and privacy-related risks.

Positioned by OpenAI as freeing up engineers to focus on reviewing and refining fixes away from repetitive detection work, Aardvark embodies the shift-left approach by exposing vulnerabilities earlier in the security process.

OpenAI claimed Aardvark has detected “meaningful vulnerabilities” within its internal codebases and those of its partners. The generative AI giant reported the tool successfully identified around 92% of issues, and when deployed on open-source projects had discovered multiple security flaws, including ten that received CVE identifiers.

The tool echoes Microsoft Security Copilot, released last year and built using OpenAI's GPT models, with Aardvark offering more of an emphasis on security at the code level.

Its release comes after concern from analysts on OpenAI’s security posture. One Gartner publication from this year reaffirmed ChatGPT poses significant security due to its experimental nature, recommending enterprises put in place access controls and impose comprehensive monitoring of all agent actions.

In a recent piece on SDxCentral, Forrester analysts argued for OpenAI to integrate support for model context protocol (MCP), the increasingly influential integration standard for AI agents with possible implications for network governance.